← Vulnerability feed

Vulnerability record · CVE-2020-17408 · published 10 September 2020

CVE-2020-17408: NEC ExpressCluster clpwebmc XXE allows unauthenticated file disclosure

Nec · Expresscluster X

NEC ExpressCluster 4.1 contains an XML External Entity (XXE) flaw in the clpwebmc executable. A remote, unauthenticated attacker can submit a crafted XML document with an external entity URI, causing the parser to fetch and embed the referenced content. Because the service runs as SYSTEM, this exposes sensitive files and data at high privilege.

7.5 CVSS 3.1 High EPSS 69% · top 0.7% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score, v2 5.0
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-10801.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote XXE with high confidentiality impact and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

NEC ExpressCluster 4.1 contains an XML External Entity (XXE) flaw in the clpwebmc executable. A remote, unauthenticated attacker can submit a crafted XML document with an external entity URI, causing the parser to fetch and embed the referenced content. Because the service runs as SYSTEM, this exposes sensitive files and data at high privilege.

Impact

An attacker gains read access to files and resources reachable by the SYSTEM-level clpwebmc process, disclosing sensitive configuration, credential or system data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via the clpwebmc component with no authentication and no user interaction required (AV:N/PR:N/UI:N). Any host exposing the affected ExpressCluster web management interface is in scope.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.7174, 99.4th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the NEC vendor patch referenced in the advisory (support.nec.co.jp id 9510100319) as the first action.
  • If patching is delayed, restrict network access to the clpwebmc web management interface to trusted management hosts only.
  • Disable external entity and DTD processing in the XML parser if configuration allows, or isolate the service.
  • Run the clpwebmc service under a least-privilege account rather than SYSTEM to limit disclosure scope.
  • Monitor NEC advisories for updated fixed versions since the record does not enumerate affected builds beyond 4.1.

Detection

  • Inspect clpwebmc and web server logs for XML requests containing DOCTYPE, ENTITY or SYSTEM/PUBLIC declarations.
  • Alert on outbound connections from the ExpressCluster host to unexpected internal or external URIs, which may indicate XXE callback or file fetch.
  • Monitor for anomalous reads of sensitive files by the clpwebmc process using file integrity or EDR telemetry.
  • Baseline normal clpwebmc request patterns and flag deviations in request size or XML structure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-17408 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34824Nec expresscluster x incorrect default permissions vulnerabilityWeak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO …EPSS 1.2%9.8CVE-2022-34825Nec expresscluster x uncontrolled search path element vulnerabilityUncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleSe…EPSS 1.3%9.8CVE-2022-34822Nec expresscluster x path traversal vulnerabilityPath traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServer…EPSS 1.5%9.8CVE-2022-34823Nec expresscluster x classic buffer overflow vulnerabilityBuffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServe…EPSS 1.4%9.8CVE-2021-20700Nec clusterpro x classic buffer overflow vulnerabilityBuffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X …EPSS 2.1%9.8CVE-2021-20701Nec clusterpro x classic buffer overflow vulnerabilityBuffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X …EPSS 2.1%9.8CVE-2021-20702Nec clusterpro x classic buffer overflow vulnerabilityBuffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUST…EPSS 2.2%9.8CVE-2021-20703Nec clusterpro x classic buffer overflow vulnerabilityBuffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUST…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2020-17408), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.