Description
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Published: 2025-05-06
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13610 Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00082}

epss

{'score': 0.00086}


Tue, 13 May 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell storage Manager
CPEs cpe:2.3:a:dell:storage_manager:16.3.20:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2016:r2.1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:*
Vendors & Products Dell
Dell storage Manager

Tue, 06 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 May 2025 16:00:00 +0000

Type Values Removed Values Added
Description Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Dell Storage Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-02-26T18:28:52.481Z

Reserved: 2025-01-07T06:04:12.135Z

Link: CVE-2025-22478

cve-icon Vulnrichment

Updated: 2025-05-06T18:48:14.211Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-06T16:15:27.210

Modified: 2025-05-13T20:17:50.513

Link: CVE-2025-22478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses