← Vulnerability feed

Vulnerability record · CVE-2020-27858 · published 20 January 2021

CVE-2020-27858: CA Arcserve D2D getNews XXE allows unauthenticated file disclosure

Arcserve · D2d

CA Arcserve D2D 16.5 contains an XML External Entity (XXE) flaw in the getNews method. Because the XML parser resolves external entity references without restriction, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. The flaw is remotely reachable without authentication and can expose sensitive data.

7.5 CVSS 3.1 High EPSS 74% · top 0.5% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score, v2 5.0
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11103.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable XXE with high confidentiality impact and very high EPSS, though not in KEV and no confirmed in-the-wild exploitation is documented.

What it is

CA Arcserve D2D 16.5 contains an XML External Entity (XXE) flaw in the getNews method. Because the XML parser resolves external entity references without restriction, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. The flaw is remotely reachable without authentication and can expose sensitive data.

Impact

An attacker can read files and other resources accessible to the affected service, which runs in the SYSTEM context, so disclosed data may include highly privileged system files. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via the getNews functionality with no authentication and no user interaction required, per the CVSS vector AV:N/PR:N/UI:N. The description does not specify the exact port or endpoint, so defenders must identify the service path themselves.

Exploitation

Not listed in CISA KEV and no public exploit references are included beyond the ZDI advisory; EPSS is high at roughly 0.738 (99.5th percentile), indicating elevated predicted exploitation likelihood.

What to do

  • Apply the vendor fix for CA Arcserve D2D 16.5 or upgrade to a supported release; patch first.
  • Disable external entity and DTD processing in the XML parser used by getNews if configuration allows.
  • Restrict network access to the D2D service so only trusted management hosts can reach it.
  • Run the D2D service under a least-privilege account rather than SYSTEM to limit file disclosure scope.
  • Monitor vendor advisories for updated guidance since the record lists no fixed version.

Detection

  • Inspect HTTP requests to the getNews endpoint for XML bodies containing DOCTYPE or ENTITY declarations.
  • Alert on outbound connections from the D2D host to unexpected internal or external URIs, which may indicate entity resolution.
  • Review D2D service logs for XML parsing errors or unusual file access patterns around getNews calls.
  • Baseline normal getNews traffic and flag anomalous request sizes or content types.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-27858 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed7.5CVE-2023-45727Proself XXE flaw allows unauthenticated file readProself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote…KEVEPSS 3.5%analysed9.8CVE-2024-34102Adobe Commerce and Magento XXE flaw allows unauthenticated code executionAdobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML do…KEVEPSS 100%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed7.5CVE-2019-13608Citrix StoreFront Server XXE allows unauthenticated file disclosureCitrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) is vulnerable to XML External Entity (XXE)…KEVEPSS 30%analysed6.5CVE-2016-9563SAP NetWeaver AS Java XXE in BC-BMT-BPM-DSK endpointThe BC-BMT-BPM-DSK component in SAP NetWeaver AS Java 7.5 fails to disable XML external entity processing, allowing XXE attacks through the sap.com~t…KEVEPSS 24%analysed

Source: NIST National Vulnerability Database (record CVE-2020-27858), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.