First published: Mon Oct 23 2023(Updated: )
Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosing local files in the file system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <5.3.0.0.5.120 | |
Dell EMC Unity XT Operating Environment | <5.3.0.0.5.120 | |
Dell EMC UnityVSA Operating Environment | <5.3.0.0.5.120 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell Unity vulnerability is CVE-2023-43067.
CVE-2023-43067 has a severity of 6.5 (medium).
The affected software for CVE-2023-43067 includes Dell Unity Operating Environment, Dell Unity Xt Operating Environment, and Dell Unityvsa Operating Environment.
An XML External Entity (XXE) injection vulnerability is a type of attack that allows an attacker to exploit vulnerable XML parsers and gain unauthorized access to sensitive data or systems.
An XXE attack can exploit CVE-2023-43067 by injecting malicious XML entities that disclose local files in the file system.