CVE-2025-36603

CVE Details

Basic Information

Title CVE-2025-36603
Type cve
Published 2025-07-21T16:20:51.358Z
Modified 2025-07-21T16:20:51.358Z

Product Information

Vendor Dell
Product AppSync
Version NA

CVSS Information

Base Score 4.2 (MEDIUM)
Attack Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Affected Products

  • Dell AppSync NA

Additional Information

CWE List CWE-611
Source dell

Description

Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.