CVE-2025-36589

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
06/01/2026
Last modified:
22/01/2026

Description

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:unisphere_for_powermax:9.2.4.18:*:*:*:*:*:*:*
cpe:2.3:a:dell:unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:* 9.2.4.17 (including) 9.2.4.19 (excluding)