Elspec Engineering G5 Digital Fault Recorder XML External Entity Vulnerability Leading to Denial-of-Service

Vulnerability

A vulnerability allowing XML External Entity (XXE) attacks has been identified in Elspec Engineering G5 Digital Fault Recorder Firmware versions through 1.2.1.12. This vulnerability allows attackers to craft XML payloads that can cause a Denial-of-Service (DoS) condition on the device.

Impact

Exploitation of this vulnerability leads to a Denial-of-Service condition, causing the device to become unresponsive or unavailable.

Remediation

Users can upgrade to Elspec G5 Digital Fault Recorder Firmware version 1.2.2.19 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.