CVE-2021-20801
Description
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cybozu Remote Service 3.1.8 to 3.1.9 has an XXE vulnerability exploitable via Firefox by an authenticated attacker, leaking stored data.
Vulnerability
An XML External Entity (XXE) vulnerability exists in Cybozu Remote Service versions 3.1.8 and 3.1.9. The issue occurs only when the product is used with Mozilla Firefox. An authenticated attacker can exploit this vulnerability via unspecified vectors, leveraging the XXE to read internal files or interact with internal resources. This is tracked as [CyVDB-1811] in the vendor's documentation [1][2].
Exploitation
An attacker must be a remote authenticated user of Cybozu Remote Service and access the product using Mozilla Firefox. The attack complexity is low, no user interaction is required, and the attack is performed over the network. The exact sequence of steps has not been publicly disclosed by the vendor [1][2].
Impact
Successful exploitation allows the attacker to obtain information stored in the product by reading files or resources via XXE. The impact on confidentiality is rated as low (limited information disclosure). There is no impact on integrity or availability [1][2].
Mitigation
The vulnerability is fixed in Cybozu Remote Service version 4.0.0, released on 2021-09-29. No workarounds are provided. According to the vendor, no fix is planned for older versions because the CVSS base score is 4.3 (Medium) [2]. This CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 3.1.8 to 3.1.9
- Cybozu, Inc./Cybozu Remote Servicev5Range: 3.1.8 to 3.1.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN52694228/index.htmlmitrex_refsource_MISC
- kb.cybozu.support/article/37423mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.