CVE-2025-36589
HIGHDell Unisphere For Powermax < 9.2.4.19 - XXE
Title source: ruleDescription
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.
Scores
CVSS v3
7.6
EPSS
0.0007
EPSS Percentile
20.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Classification
CWE
CWE-611
Status
published
Affected Products (2)
dell/unisphere_for_powermax
dell/unisphere_for_powermax_virtual_appliance
< 9.2.4.19
Timeline
Published
Jan 06, 2026
Tracked Since
Feb 18, 2026