8.1
CVE-2025-22478
- EPSS 0.28%
- Veröffentlicht 06.05.2025 15:55:03
- Zuletzt bearbeitet 13.05.2025 20:17:50
- Erkennungen
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Storage Manager Version 16.3.20
Dell ≫ Storage Manager Version 2016 Update r2.1
Dell ≫ Storage Manager Version 2020 Update r1
Dell ≫ Storage Manager Version 2020 Update r1.10
Dell ≫ Storage Manager Version 2020 Update r1.2
Dell ≫ Storage Manager Version 2020 Update r1.20
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.197 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| EMC | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://www.dell.com/support/kbdoc/en-us/000317318/dsa-2025-191-security-update-for-storage-center-dell-storage-manager-vulnerabilities