Sceawere
Vulnerability Detail
CVE-2026-101893UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DYMO ID XML External Entity
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 2h ago
- Vendor
- Newell Brands
- Product
- DYMO ID
- Attack Type
- CWE-611 Improper Restriction of XML External Entity Reference
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or crash the process. Fixed in 1.6.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-10-05T21:16:32.227Z",
"pubdate": "2026-10-05T21:16:32.227Z",
"executiveSummary": "Newell Brands DYMO ID version 1.5.1.71 is susceptible to an XML External Entity (XXE) vulnerability resulting from the insecure implementation of the XmlDocument.Load() method.\nThe application automatically parses job files upon directory traversal, enabling an attacker to trigger the vulnerability simply by placing a crafted file within a browsed network share or directory.\nThe impact of this flaw is severe, allowing for Server-Side Request Forgery (SSRF), the exfiltration of NTLMv2 hashes, unauthorized local file system read access, and potential application denial-of-service through process crashing.\nThe vulnerability does not require authentication to trigger, as the parsing mechanism is invoked during folder browse operations.\nThe risk to organizations is significant, particularly if the software is utilized in environments where users may browse untrusted or shared network locations.\nThe issue has been formally addressed in version 1.6.0, which enforces secure XML processing practices.",
"technicalDetails": "The vulnerability originates from the default behavior of the System.Xml.XmlDocument.Load() function in the .NET framework, which historically permits Document Type Definition (DTD) processing and external entity resolution when not explicitly configured otherwise.\nDYMO ID 1.5.1.71 fails to instantiate an XmlReader with ProhibitDtd or DtdProcessing set to Prohibit, thereby leaving the XML parser vulnerable to malicious entity declarations.\nThe attack vector is uniquely facilitated by the software's automated file-handling logic. Specifically, the 'PC Job Files' view functionality is designed to scan and parse files with recognized job extensions as soon as the user navigates to a directory containing them.\nAn attacker can exploit this by depositing a specially crafted XML job file onto a network share or local folder accessible by the victim. Once the user browses the directory, the DYMO ID application automatically triggers the XML parser on the malicious file.\nThe exploit sequence operates as follows: First, the attacker embeds a malicious DTD reference within the XML job file, targeting an external resource or local system path. Second, upon browsing, the XmlDocument.Load() function processes this DTD. Third, if an external URI is provided, the application attempts to fetch the resource, enabling SSRF. If the resource is on an SMB share, the underlying OS may attempt to authenticate using the NTLMv2 protocol, allowing the attacker to capture the user's NTLMv2 challenge-response hash for subsequent offline cracking. Furthermore, by using local file paths (e.g., file:///c:/windows/win.ini), the attacker can force the application to read and potentially exfiltrate sensitive local file contents.\nAdditionally, providing malformed XML structures or deeply nested entities can exhaust system resources, leading to a crash of the DYMO ID process, effectively causing a local denial-of-service condition.\nThis vulnerability is particularly potent because it effectively turns a passive file-viewing action into an active security compromise, requiring no direct interaction from the user beyond the act of browsing a compromised filesystem path.\nThe vulnerable component is identified within the file processing sub-routines responsible for parsing job data in version 1.5.1.71. There are no authentication requirements for this exploitation, as the parser executes as the user browsing the directory."
}