CVE-2025-36603: Dell Appsync
Medium severity, CVSS 4.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
Affected products
- Dell Appsync: before 4.6.0.4 (fixed in 4.6.0.4)
Published 2025-07-21. Last modified 2026-06-17.