Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.
Metrics
Affected Vendors & Products
History
Wed, 07 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell unisphere For Powermax |
|
| Vendors & Products |
Dell
Dell unisphere For Powermax |
Tue, 06 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-01-06T16:55:17.429Z
Reserved: 2025-04-15T21:31:17.347Z
Link: CVE-2025-36589
Updated: 2026-01-06T16:55:06.485Z
Status : Received
Published: 2026-01-06T17:15:43.780
Modified: 2026-01-06T17:15:43.780
Link: CVE-2025-36589
No data.
OpenCVE Enrichment
Updated: 2026-01-07T10:08:47Z