Vulnerability Details CVE-2025-36603
Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.7%
CVSS Severity
CVSS v3 Score 4.2
Products affected by CVE-2025-36603
-
cpe:2.3:a:dell:appsync:4.6.0.0
-
cpe:2.3:a:dell:appsync:4.6.0.3