Impact
The vulnerability is in DYMO ID 1.5.1.71, which parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses any recognized job file extension when a folder is browsed. A crafted file placed on a network share that the user browses can trigger SSRF, capture NTLMv2 credentials, read local files, or crash the application. The weakness corresponds to CWE‑611 (XML External Entity).
Affected Systems
Newell Brands DYMO ID, version 1.5.1.71. The issue has been fixed in version 1.6.0. No other vendors or products are affected according to the CNA data.
Risk and Exploitability
The CVSS base score is 5.1, indicating a moderate level of risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a user to browse a folder that contains a malicious file shared over the network, which could allow the attacker to capture NTLMv2 credentials, issue SSRF requests, read local files, or crash the application. While the vulnerability is client side, the need for folder browsing and the confidentiality of the target limits its exploitability compared to server‑side weaknesses, but it remains a concern for environments where users routinely access network shares.
OpenCVE Enrichment