CVE-2017-9095 is an XML External Entity (XXE) vulnerability affecting Diving Log 6.0. It allows an unauthenticated attacker to remotely view local files on a victim's system by crafting a malicious dive.xml file that is processed during a Subsurface import. This vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity requiring user interaction, but leading to high confidentiality impact. While not observed in active exploitation (KEV: No), public exploit code exists on ExploitDB, though there is no evidence of widespread community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.9CPE matchmatch criteria | cpe:2.3:a:divinglog:diving_log:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.