Description
Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External Entity Reference vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
Problem types
CWE-611: Improper Restriction of XML External Entity Reference
Product status
8.0
Credits
Dell would like to thank n3k From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue
References
www.dell.com/...rity-update-for-dell-cloudlink-vulnerability