CVE-2016-5795: Automatedlogic I-Vu
High severity, CVSS 7.3. EPSS: 2.2% chance of exploitation in the next 30 days.
An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.
Affected products
- Automatedlogic I-Vu: up to and including 6.5
- Automatedlogic Sitescan Web: up to and including 6.5
- Carrier Automatedlogic Webctrl: up to and including 6.5
Published 2017-08-31. Last modified 2026-06-17.