CVE-2025-36589

HIGH

Dell Unisphere For Powermax < 9.2.4.19 - XXE

Title source: rule

Description

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.

Scores

CVSS v3 7.6
EPSS 0.0007
EPSS Percentile 20.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Classification

CWE
CWE-611
Status published

Affected Products (2)

dell/unisphere_for_powermax
dell/unisphere_for_powermax_virtual_appliance < 9.2.4.19

Timeline

Published Jan 06, 2026
Tracked Since Feb 18, 2026