Impact
Dell Unisphere for PowerMax versions 10.3.0.5 and earlier are affected by a flaw that allows an attacker to supply crafted XML containing external entity references. The software does not properly restrict the use of XML External Entity requests, enabling the resolution of these entities and potentially exposing internal information. The advisory describes the result as unauthorized access, and does not state that the vulnerability supports denial of service or code execution. Based on the description, the possibility of internal data exposure is inferred, though not explicitly stated in the CVE text.
Affected Systems
Dell Unisphere for PowerMax, versions up to and including 10.3.0.5 are affected. No other product variants are documented in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of < 1% shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires remote network access to the Unisphere XML service and can be performed by an attacker with low privileges. The primary risk is unauthorized data access rather than privilege escalation or remote code execution. Systems exposed to untrusted networks should still apply the fix or otherwise mitigate the exposure.
OpenCVE Enrichment