Dell Unisphere for PowerMax Improper XML External Entity Reference Vulnerability

Vulnerability

A vulnerability allowing improper restriction of XML external entity references has been identified in Dell Unisphere for PowerMax versions 9.2.4.x. This vulnerability could be exploited by a low-privileged attacker with remote access, potentially leading to unauthorized access to data and resources outside of the intended control.

Impact

Exploitation of this vulnerability could result in unauthorized access to data and resources beyond the user's intended control.

Remediation

Users can upgrade to version 9.2.4.19 or later. For Unisphere for PowerMax Virtual Appliance, version 9.2.4.19 or later is recommended. Instructions for downloading the update are available on the Dell Unisphere for PowerMax drivers page.

Added: Jan 6, 2026, 5:34 PM
Updated: Jan 6, 2026, 5:34 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
4.9
remediation
7.7
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.