CVE-2019-14258: Zenoss

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

Affected products

  • Zenoss Zenoss: version 2.5.3 only

Published 2019-08-21. Last modified 2026-06-17.