570
VMScore

CVE-2021-21517

Published: 01/03/2021 Updated: 08/03/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.2 | Impact Score: 2.7 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc srs policy manager 6.6

dell emc srs policy manager 6.8.3

dell emc srs policy manager 6.9.0