ZeroHour

CVE-2024-53675

moderate

XXE Information-Disclosure Vulnerability in HPE Insight Remote Support

CVSS 3.1
7.5 high
EPSS
84%p100
Published
()
Modified
AI analysis

CVE-2024-53675 is an XML external entity injection (XXE) flaw in HPE Insight Remote Support arising from improper handling of XML input (CWE-611, CWE-91). An attacker with network reachability to the product's XML-processing interface can send crafted XML containing external entity references, which the parser resolves, with no authentication or user interaction required per the CVSS vector. Successful exploitation primarily yields disclosure of sensitive information, such as reading files from the server hosting the service, potentially including credentials or configuration data. Organizations running HPE Insight Remote Support, which is typically deployed as an on-premises server in enterprise datacenters to support and monitor HPE infrastructure, are affected. Exploitation has not yet been confirmed in the wild and no public proof-of-concept is known, but the EPSS score of 83.6% (100th percentile) indicates a high probability of exploitation within the next 30 days.

What to do: Apply the vendor fix referenced in the HPE security bulletin for CVE-2024-53675 (the available data does not specify version numbers, so do not assume a specific fixed release without checking the advisory). Until patched, restrict network access to the Insight Remote Support service to trusted management networks and, where configurable, disable or limit external entity resolution in XML parsing. Given the very high EPSS score, treat patching as a near-term priority even though exploitation has not yet been confirmed.

Affected
HPE Insight Remote Support
Estimated exposure
moderatelikely on the order of thousands of enterprise deployments; exact install base unknown — Insight Remote Support is an enterprise on-premises support/monitoring product typically deployed as a single server per site by organizations with HPE server support agreements, suggesting thousands of installations rather than mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Vendors
hpe
Products
insight remote support
Weakness
CWE-91, CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.