CVE-2024-39586

LOW

Dell EMC AppSync 4.3-4.6 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

Scores

CVSS v3 2.9
EPSS 0.0021
EPSS Percentile 11.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
dell/emc_appsync 4.3.0.0 - 4.6.0.3
Published Oct 09, 2024
Tracked Since Feb 18, 2026