Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-39586


Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading to information disclosure.


Published

2024-10-09T07:15:09.473

Last Modified

2024-10-17T14:30:02.843

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 2.9 (LOW)

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_appsync < 4.6.0.3 Yes

References