PT-2024-2581 · Dell · Dell Powerprotect Data Manager

Published

2024-02-13

·

Updated

2025-01-27

·

CVE-2024-25971

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:M/C:C/I:N/A:P
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Manager version 19.15
Description The issue is related to an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service. The vulnerability is associated with incorrect restriction of XML links to external objects, which could allow an attacker to gain unauthorized access to confidential data or cause a denial of service.
Recommendations For Dell PowerProtect Data Manager version 19.15, consider disabling the XML external entity injection functionality until a patch is available. Restrict access to sensitive data and configure the system to limit the impact of a potential denial-of-service attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

BDU:2024-02640
CVE-2024-25971

Affected Products

Dell Powerprotect Data Manager