CVE-2025-22478

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:storage_manager:16.3.20:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2016:r2.1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:*

History

13 May 2025, 20:17

Type Values Removed Values Added
First Time Dell
Dell storage Manager
References () https://www.dell.com/support/kbdoc/en-us/000317318/dsa-2025-191-security-update-for-storage-center-dell-storage-manager-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000317318/dsa-2025-191-security-update-for-storage-center-dell-storage-manager-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CPE cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:16.3.20:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2016:r2.1:*:*:*:*:*:*

06 May 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-06 16:15

Updated : 2025-05-13 20:17


NVD link : CVE-2025-22478

Mitre link : CVE-2025-22478


JSON object : View

Products Affected

dell

  • storage_manager
CWE
CWE-611

Improper Restriction of XML External Entity Reference