GPU VulnDB

Database/Control plane, storage & DevOps

HPE Insight Remote Support: XML external entity injection allows remote disclosure of server information

CVSS 7.3CVE-2024-11622Control plane, storage & DevOps+2 more CVEscurated

Impact

An unauthenticated remote attacker can submit crafted XML to Insight Remote Support and read files or other information from the IRS server. HPE assigned three separate ids (CVE-2024-11622, CVE-2024-53674, CVE-2024-53675) to distinct XXE parsing paths, but all are the same flaw class in the same component with the same effect and the same fix.

Who can reach it

Unauthenticated network access.

What to do

Apply the update in HPE advisory HPESBGN04731 (Insight Remote Support 7.14.0.629 or later); the single patch closes all three XXE ids at once.

Also covers 2 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2024-53674CVE-2024-53675

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.