CVE-2021-21517: XEE
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21517?
CVE-2021-21517 is classified as a critical vulnerability due to its potential for remote exploitation and significant impact.
How do I fix CVE-2021-21517?
To fix CVE-2021-21517, update your Dell EMC SRS Policy Manager to version 6.6, 6.8.3, or 6.9.0 as recommended in the security update.
What versions of Dell EMC SRS Policy Manager are affected by CVE-2021-21517?
CVE-2021-21517 affects Dell EMC SRS Policy Manager versions 6.6, 6.8.3, and 6.9.0.
Can CVE-2021-21517 be exploited by authenticated users?
No, CVE-2021-21517 can be exploited by remote unauthenticated attackers.
What kind of attack is possible with CVE-2021-21517?
CVE-2021-21517 allows a remote attacker to perform an XML External Entity Injection (XXE) attack to potentially read sensitive system files.