PT-2024-2581 · Dell · Dell Powerprotect Data Manager
Published
2024-02-13
·
Updated
2025-01-27
·
CVE-2024-25971
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:M/C:C/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Dell PowerProtect Data Manager version 19.15
Description
The issue is related to an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service. The vulnerability is associated with incorrect restriction of XML links to external objects, which could allow an attacker to gain unauthorized access to confidential data or cause a denial of service.
Recommendations
For Dell PowerProtect Data Manager version 19.15, consider disabling the XML external entity injection functionality until a patch is available. Restrict access to sensitive data and configure the system to limit the impact of a potential denial-of-service attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Powerprotect Data Manager