CVE-2025-46425

MEDIUM

Dell Storage Center - Dell Storage Manager <20.1.20 - XML External ...

Title source: llm
STIX 2.1

Description

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-611
Status published
Products (2)
dell/storage_manager 2020 r1 (4 CPE variants)
dell/storage_manager < 2020
Published Oct 24, 2025
Tracked Since Feb 18, 2026