CVE-2025-22478

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:storage_manager:16.3.20:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2016:r2.1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:*

History

13 May 2025, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-06 16:15

Updated : 2025-05-13 20:17


NVD link : CVE-2025-22478

Mitre link : CVE-2025-22478

CVE.ORG link : CVE-2025-22478


JSON object : View

Products Affected

dell

  • storage_manager
CWE
CWE-611

Improper Restriction of XML External Entity Reference