CVE-2024-39586

LOW

Dell Emc Appsync < 4.6.0.3 - XXE

Title source: rule
STIX 2.1

Description

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

Scores

CVSS v3 2.9
EPSS 0.0005
EPSS Percentile 15.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
dell/emc_appsync 4.3.0.0 - 4.6.0.3
Published Oct 09, 2024
Tracked Since Feb 18, 2026