PT-2024-35805 · Hewlett Packard · Hpe Insight Remote Support

Published

2024-11-26

·

Updated

2024-12-12

·

CVE-2024-53674

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HPE Insight Remote Support (affected versions not specified)
Description A vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases due to an XML external entity injection (XXE) issue. This could potentially lead to information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2024-53674
ZDI-24-1637

Affected Products

Hpe Insight Remote Support