Executive brief
NSA GRASSMARLIN, a tool used for mapping and visualizing Industrial Control Systems (ICS) and network topologies, is vulnerable to a flaw that could allow an attacker to access sensitive information. By providing specially crafted session data, an attacker could exploit the way the software processes XML files to read local system data. Because the project reached end-of-life status in 2017, no official patches will be released, and users are advised to migrate to supported alternatives or implement strict access controls.
Technical details
A vulnerability classified as Improper Restriction of XML External Entity Reference (XXE) exists in NSA GRASSMARLIN (specifically confirmed in v3.2.1). The flaw is rooted in insufficient hardening of the XML parsing component when processing session data. A local attacker with low privileges can provide a crafted XML-based session file that triggers the parser to resolve external entities, potentially leading to the disclosure of sensitive local files or internal network information. As the product has been end-of-life (EOL) since 2017, the vendor has stated that no patches will be issued.
Affected products
- NSA GRASSMARLIN All versions up to and including 3.2.1
Timeline
- 2017: other: Project reached end-of-life (EOL) status
- 2026-04-28: advisory: Initial publication of ICSA-26-118-01