Description
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-07-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Unisphere for PowerMax versions 10.3.0.5 and earlier are affected by a flaw that allows an attacker to supply crafted XML containing external entity references. The software does not properly restrict the use of XML External Entity requests, enabling the resolution of these entities and potentially exposing internal information. The advisory describes the result as unauthorized access, and does not state that the vulnerability supports denial of service or code execution. Based on the description, the possibility of internal data exposure is inferred, though not explicitly stated in the CVE text.

Affected Systems

Dell Unisphere for PowerMax, versions up to and including 10.3.0.5 are affected. No other product variants are documented in the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of < 1% shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires remote network access to the Unisphere XML service and can be performed by an attacker with low privileges. The primary risk is unauthorized data access rather than privilege escalation or remote code execution. Systems exposed to untrusted networks should still apply the fix or otherwise mitigate the exposure.

Generated by OpenCVE AI on July 28, 2026 at 08:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the vendor‑published patch or upgrade to the latest Dell Unisphere for PowerMax release.
  • Place Unisphere behind a firewall, allowing traffic only from trusted management nodes and blocking external XML submission services.
  • Configure the Unisphere XML parser to disable or restrict external entity processing, if such an option is available.

Generated by OpenCVE AI on July 28, 2026 at 08:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Restriction of XML External Entity Reference in Dell Unisphere for PowerMax

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Improper Restriction of XML External Entity Reference in Dell Unisphere for PowerMax

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Improper XML External Entity Reference in Dell Unisphere for PowerMax

Thu, 16 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper XML External Entity Reference in Dell Unisphere for PowerMax

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Restriction of XML External Entity Reference in Dell Unisphere for PowerMax

Mon, 13 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Improper Restriction of XML External Entity Reference in Dell Unisphere for PowerMax

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Insecure XML External Entity Handling in Dell Unisphere for PowerMax

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Insecure XML External Entity Handling in Dell Unisphere for PowerMax

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell unisphere For Powermax
Vendors & Products Dell
Dell unisphere For Powermax
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Unisphere For Powermax
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-10T14:43:05.838Z

Reserved: 2026-06-15T16:28:29.012Z

Link: CVE-2026-54470

cve-icon Vulnrichment

Updated: 2026-07-10T14:43:00.738Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference