CVE-2024-53675

Published Nov 26, 2024

Last updated 4 months ago

Overview

Description
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
Source
security-alert@hpe.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

security-alert@hpe.com
CWE-91
nvd@nist.gov
CWE-611

Social media

Hype score
Not currently trending
  1. #Vulnerability #CVE202453675 CVE-2024-53675: PoC Exploit Released for HPE Insight RS XML Injection Flaw https://t.co/rtlVcZWtpy https://t.co/rIFQVwE3HG

    @Komodosec

    7 Apr 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. آسیب پذیری CVE-2024-53675: انتشار PoC اکسپلویت برای آسیب‌پذیری تزریق XML در HPE Insight RS #Cyber_Security_News #اخبار_امنیت_سایبری #Android #cellebrite #CVE_2024_53675 #HPE https://t.co/UAgoR1zziS

    @vulnerbyte

    3 Mar 2025

    19 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-53675: PoC Exploit Released for HPE Insight RS XML Injection Flaw https://t.co/iJtDTUwBIL https://t.co/2CF8V95GW5

    @freedomhack101

    2 Mar 2025

    51 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ Vulnerability Alert: HPE Insight Remote Support XML Injection Vulnerability 📅 Timeline: Disclosure: 2024-11-26, Patch: 2025-03-01 🆔cveId: CVE-2024-53675 📊baseScore: 7.3 📏cvssMetrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L cvssSeverity: High 🟠 🛠️exploitMaturity

    @syedaquib77

    1 Mar 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 『These vulnerabilities could remotely allow a directory traversal, disclosure of information, or code execution.』 CVE-2024-11622 CVE-2024-53673 CVE-2024-53674 CVE-2024-53675 CVE-2024-53676 HPE Insight Remote Support (IRS), Multiple Vulnerabilities https://t.co/gnsqxwfhqu

    @autumn_good_35

    28 Nov 2024

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-53675 An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. https://t.co/HofQDfhWcg

    @CVEnew

    26 Nov 2024

    527 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations