Impact
Dell Command Update (DCU) versions before 5.7.1 include an Improper Restriction of XML External Entity Reference flaw (CWE-611). A low‑privileged user with local access could supply crafted XML input, causing the application to resolve external entities and thereby elevate privileges on the host and potentially perform server‑side request forgery to access internal resources.
Affected Systems
The vulnerability affects Dell Command Update software on Dell systems running any version prior to 5.7.1. Users running earlier releases of DCU are exposed unless updated.
Risk and Exploitability
With a CVSS score of 6.5 the issue is considered moderate‑to‑high severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV. The exploitation model requires local access by a low‑privileged account; an attacker would need to run DCU with malicious XML input, making remote exploitation unlikely but local privilege escalation possible.
OpenCVE Enrichment