Vulnerability CVE-2023-23595


Published: 2023-01-15

Description:
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE; 2.x versions are no longer supported. There is no available information about whether any later version is affected.

 References:
https://bluecatnetworks.com/integrations/adaptive-application/device-registration-portal-drp/
https://github.com/colemanjp/XXE-Vulnerability-in-Bluecat-Device-Registration-Portal-DRP
https://everything.curl.dev/usingcurl/netrc

Copyright 2026, cxsecurity.com

 

Back to Top