ZDI-24-1638: Hewlett Packard Enterprise Insight Remote Support validateAgainstXSD XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Hewlett Packard Enterprise Insight Remote Support. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2024-53675.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1638?
The vulnerability ZDI-24-1638 has a CVSS rating of 7.3, indicating a high severity level.
What impact does ZDI-24-1638 have on systems?
ZDI-24-1638 allows remote attackers to disclose sensitive information without requiring authentication.
Which software is affected by ZDI-24-1638?
The vulnerability ZDI-24-1638 affects Hewlett Packard Enterprise Insight Remote Support installations.
How can I mitigate the risks of ZDI-24-1638?
To mitigate ZDI-24-1638, ensure that you apply available updates from Hewlett Packard Enterprise for Insight Remote Support.
Is authentication required to exploit ZDI-24-1638?
No, authentication is not required to exploit the ZDI-24-1638 vulnerability.