CVE-2024-53674
moderateUnauthenticated XXE Information Disclosure in HPE Insight Remote Support
CVE-2024-53674 is an XML external entity (XXE) injection flaw in HPE Insight Remote Support, an on-premises support and monitoring product used alongside HPE servers and storage. Because the flaw requires no authentication (AV:N, PR:N, AC:L per the CVSS vector), a remote attacker who can reach the affected service can submit crafted XML with external entity references that the parser resolves, reading files from the local system and potentially probing internal resources. The impact is confined to information disclosure (high confidentiality impact, no integrity or availability loss), though disclosed data such as configuration files or stored credentials could enable follow-on attacks. Any organization running HPE Insight Remote Support is affected, with the highest risk where the service is reachable from untrusted or internet-facing networks. No public proof-of-concept or confirmed in-the-wild exploitation has been reported yet, but the elevated EPSS score (46.7% probability of exploitation within 30 days, 99th percentile) indicates exploitation is likely soon, so prompt patching is warranted.
What to do: Upgrade to the fixed release specified in HPE's security bulletin for CVE-2024-53674, since exact vulnerable versions are not included in this data. Until patching, restrict network access to the Insight Remote Support service to trusted management networks, limit unnecessary outbound connectivity from it, and review logs for unexpected XML requests or file access. If the deployed version is near end-of-support, consider migrating to HPE's current support and monitoring tooling.
| HPE Insight Remote Support | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
- Vendors
- hpe
- Products
- insight remote support
- Weakness
- CWE-91, CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.