CVE Published: 28/03/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: dell |
Vendor: Dell |
Product: PowerProtect Data Manager Status : PUBLISHED
CVE-2024-25971 Description
Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to information disclosure, denial-of-service.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L