ZeroHour

CVE-2024-53674

moderate

Unauthenticated XXE Information Disclosure in HPE Insight Remote Support

CVSS 3.1
7.5 high
EPSS
47%p99
Published
()
Modified
AI analysis

CVE-2024-53674 is an XML external entity (XXE) injection flaw in HPE Insight Remote Support, an on-premises support and monitoring product used alongside HPE servers and storage. Because the flaw requires no authentication (AV:N, PR:N, AC:L per the CVSS vector), a remote attacker who can reach the affected service can submit crafted XML with external entity references that the parser resolves, reading files from the local system and potentially probing internal resources. The impact is confined to information disclosure (high confidentiality impact, no integrity or availability loss), though disclosed data such as configuration files or stored credentials could enable follow-on attacks. Any organization running HPE Insight Remote Support is affected, with the highest risk where the service is reachable from untrusted or internet-facing networks. No public proof-of-concept or confirmed in-the-wild exploitation has been reported yet, but the elevated EPSS score (46.7% probability of exploitation within 30 days, 99th percentile) indicates exploitation is likely soon, so prompt patching is warranted.

What to do: Upgrade to the fixed release specified in HPE's security bulletin for CVE-2024-53674, since exact vulnerable versions are not included in this data. Until patching, restrict network access to the Insight Remote Support service to trusted management networks, limit unnecessary outbound connectivity from it, and review logs for unexpected XML requests or file access. If the deployed version is near end-of-support, consider migrating to HPE's current support and monitoring tooling.

Affected
HPE Insight Remote Support
Estimated exposure
moderateplausibly tens of thousands of enterprise deployments, with likely only a minority exposed to untrusted networks — Insight Remote Support has long been deployed at enterprises managing HPE server and storage fleets, but it typically runs on internal management networks rather than being internet-exposed, so this is a deployment-pattern estimate rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Vendors
hpe
Products
insight remote support
Weakness
CWE-91, CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.