Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-2374

27
FAUCET Score

CVE-2024-2374 is an XML External Entity (XXE) injection vulnerability affecting multiple WSO2 products. The flaw stems from improper XML parser configuration that fails to disable external entity resolution, enabling attackers to supply malicious XML payloads that reference external resources. This misconfiguration creates a critical security gap in how these products process user-supplied XML data. The vulnerability carries a CVSS score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning exploitation can be executed reliably by threat actors. An attacker can leverage this vulnerability to conduct information disclosure attacks by reading sensitive files from the file system, access HTTP resources available to the affected product, and execute denial of service attacks through resource exhaustion via recursive entity expansion or fetching large external resources. Currently, this vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.00014 indicates minimal current exploitation probability. However, the moderate FAUCET Risk Score of 43.0/100 suggests organizations should prioritize patching, particularly those operating internet-facing WSO2 deployments, as the straightforward nature of XXE exploitation combined with critical impact warrants prompt remediation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.1.0, < 3.1.0.278CPE matchmatch criteria
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
>= 3.2.0, < 3.2.0.368CPE matchmatch criteria
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.0.0.280CPE matchmatch criteria
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
>= 4.1.0, < 4.1.0.206CPE matchmatch criteria
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*
>= 4.2.0, < 4.2.0.144CPE matchmatch criteria
cpe:2.3:a:wso2:api_manager:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 7th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

security.docs.wso2.com / en/latest/security-announcements/security-advisories/2026/WSO2-2024-3255
Vendor Advisory