Vulnerability record · CVE-2020-17408 · published 10 September 2020
CVE-2020-17408: NEC ExpressCluster clpwebmc XXE allows unauthenticated file disclosure
Nec · Expresscluster X
NEC ExpressCluster 4.1 contains an XML External Entity (XXE) flaw in the clpwebmc executable. A remote, unauthenticated attacker can submit a crafted XML document with an external entity URI, causing the parser to fetch and embed the referenced content. Because the service runs as SYSTEM, this exposes sensitive files and data at high privilege.
Description
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-10801.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote XXE with high confidentiality impact and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
NEC ExpressCluster 4.1 contains an XML External Entity (XXE) flaw in the clpwebmc executable. A remote, unauthenticated attacker can submit a crafted XML document with an external entity URI, causing the parser to fetch and embed the referenced content. Because the service runs as SYSTEM, this exposes sensitive files and data at high privilege.
Impact
An attacker gains read access to files and resources reachable by the SYSTEM-level clpwebmc process, disclosing sensitive configuration, credential or system data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via the clpwebmc component with no authentication and no user interaction required (AV:N/PR:N/UI:N). Any host exposing the affected ExpressCluster web management interface is in scope.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.7174, 99.4th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the NEC vendor patch referenced in the advisory (support.nec.co.jp id 9510100319) as the first action.
- If patching is delayed, restrict network access to the clpwebmc web management interface to trusted management hosts only.
- Disable external entity and DTD processing in the XML parser if configuration allows, or isolate the service.
- Run the clpwebmc service under a least-privilege account rather than SYSTEM to limit disclosure scope.
- Monitor NEC advisories for updated fixed versions since the record does not enumerate affected builds beyond 4.1.
Detection
- Inspect clpwebmc and web server logs for XML requests containing DOCTYPE, ENTITY or SYSTEM/PUBLIC declarations.
- Alert on outbound connections from the ExpressCluster host to unexpected internal or external URIs, which may indicate XXE callback or file fetch.
- Monitor for anomalous reads of sensitive files by the clpwebmc process using file integrity or EDR telemetry.
- Baseline normal clpwebmc request patterns and flag deviations in request size or XML structure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.support.nec.co.jp/en/View.aspx?id=9510100319 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1102/ | Third Party AdvisoryVDB Entry |
| https://www.support.nec.co.jp/en/View.aspx?id=9510100319 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1102/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-17408 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17408), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.