Vulnerability record · CVE-2020-27858 · published 20 January 2021
CVE-2020-27858: CA Arcserve D2D getNews XXE allows unauthenticated file disclosure
Arcserve · D2d
CA Arcserve D2D 16.5 contains an XML External Entity (XXE) flaw in the getNews method. Because the XML parser resolves external entity references without restriction, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. The flaw is remotely reachable without authentication and can expose sensitive data.
Description
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11103.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable XXE with high confidentiality impact and very high EPSS, though not in KEV and no confirmed in-the-wild exploitation is documented.
What it is
CA Arcserve D2D 16.5 contains an XML External Entity (XXE) flaw in the getNews method. Because the XML parser resolves external entity references without restriction, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. The flaw is remotely reachable without authentication and can expose sensitive data.
Impact
An attacker can read files and other resources accessible to the affected service, which runs in the SYSTEM context, so disclosed data may include highly privileged system files. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via the getNews functionality with no authentication and no user interaction required, per the CVSS vector AV:N/PR:N/UI:N. The description does not specify the exact port or endpoint, so defenders must identify the service path themselves.
Exploitation
Not listed in CISA KEV and no public exploit references are included beyond the ZDI advisory; EPSS is high at roughly 0.738 (99.5th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Apply the vendor fix for CA Arcserve D2D 16.5 or upgrade to a supported release; patch first.
- Disable external entity and DTD processing in the XML parser used by getNews if configuration allows.
- Restrict network access to the D2D service so only trusted management hosts can reach it.
- Run the D2D service under a least-privilege account rather than SYSTEM to limit file disclosure scope.
- Monitor vendor advisories for updated guidance since the record lists no fixed version.
Detection
- Inspect HTTP requests to the getNews endpoint for XML bodies containing DOCTYPE or ENTITY declarations.
- Alert on outbound connections from the D2D host to unexpected internal or external URIs, which may indicate entity resolution.
- Review D2D service logs for XML parsing errors or unusual file access patterns around getNews calls.
- Baseline normal getNews traffic and flag anomalous request sizes or content types.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-20-1397/ | Third Party AdvisoryVDB Entry |
| https://www.zerodayinitiative.com/advisories/ZDI-20-1397/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-27858 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-27858), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.