Description
Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or crash the process. Fixed in 1.6.0.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Credential Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is in DYMO ID 1.5.1.71, which parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses any recognized job file extension when a folder is browsed. A crafted file placed on a network share that the user browses can trigger SSRF, capture NTLMv2 credentials, read local files, or crash the application. The weakness corresponds to CWE‑611 (XML External Entity).

Affected Systems

Newell Brands DYMO ID, version 1.5.1.71. The issue has been fixed in version 1.6.0. No other vendors or products are affected according to the CNA data.

Risk and Exploitability

The CVSS base score is 5.1, indicating a moderate level of risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a user to browse a folder that contains a malicious file shared over the network, which could allow the attacker to capture NTLMv2 credentials, issue SSRF requests, read local files, or crash the application. While the vulnerability is client side, the need for folder browsing and the confidentiality of the target limits its exploitability compared to server‑side weaknesses, but it remains a concern for environments where users routinely access network shares.

Generated by OpenCVE AI on October 5, 2026 at 22:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to DYMO ID 1.6.0 or later, which disables DTD processing in job file parsing.
  • Restrict or remove user access to untrusted network shares that are browsed by the PC Job Files view, ensuring that only trusted directories are included in the browse list.
  • If an immediate upgrade is not possible, disable the PC Job Files feature or configure the application to prevent folder browsing on any network share until a fix is applied.

Generated by OpenCVE AI on October 5, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or crash the process. Fixed in 1.6.0.
Title Newell Brands DYMO ID document parsing failing file type extension authentication check
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-05T20:36:21.380Z

Reserved: 2026-09-28T15:54:45.621Z

Link: CVE-2026-101893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:32.227

Modified: 2026-10-05T21:16:32.227

Link: CVE-2026-101893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T23:00:19Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference