Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 13 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell storage Manager |
|
| CPEs | cpe:2.3:a:dell:storage_manager:16.3.20:*:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2016:r2.1:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:* cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:* |
|
| Vendors & Products |
Dell
Dell storage Manager |
Tue, 06 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 May 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published: 2025-05-06T15:55:03.918Z
Updated: 2025-05-08T03:56:09.072Z
Reserved: 2025-01-07T06:04:12.135Z
Link: CVE-2025-22478
Updated: 2025-05-06T18:48:14.211Z
Status : Analyzed
Published: 2025-05-06T16:15:27.210
Modified: 2025-05-13T20:17:50.513
Link: CVE-2025-22478
No data.