CVE-2025-36589
XXE Vulnerability in Dell Unisphere for PowerMax Allows Data Access
Publication date: 2026-01-06
Last updated on: 2026-01-06
Assigner: Dell
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | unisphere_for_powermax | 9.2.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Restriction of XML External Entity (XXE) Reference in Dell Unisphere for PowerMax version 9.2.4.x. It allows a low privileged attacker with remote access to exploit the system by manipulating XML input, potentially leading to unauthorized access to data and resources outside the intended control.
How can this vulnerability impact me? :
Exploitation of this vulnerability can lead to unauthorized access to sensitive data and resources beyond what is intended, which may result in data breaches, information disclosure, and potential disruption of services.