CVE-2024-53675
moderateXXE Information-Disclosure Vulnerability in HPE Insight Remote Support
CVE-2024-53675 is an XML external entity injection (XXE) flaw in HPE Insight Remote Support arising from improper handling of XML input (CWE-611, CWE-91). An attacker with network reachability to the product's XML-processing interface can send crafted XML containing external entity references, which the parser resolves, with no authentication or user interaction required per the CVSS vector. Successful exploitation primarily yields disclosure of sensitive information, such as reading files from the server hosting the service, potentially including credentials or configuration data. Organizations running HPE Insight Remote Support, which is typically deployed as an on-premises server in enterprise datacenters to support and monitor HPE infrastructure, are affected. Exploitation has not yet been confirmed in the wild and no public proof-of-concept is known, but the EPSS score of 83.6% (100th percentile) indicates a high probability of exploitation within the next 30 days.
What to do: Apply the vendor fix referenced in the HPE security bulletin for CVE-2024-53675 (the available data does not specify version numbers, so do not assume a specific fixed release without checking the advisory). Until patched, restrict network access to the Insight Remote Support service to trusted management networks and, where configurable, disable or limit external entity resolution in XML parsing. Given the very high EPSS score, treat patching as a near-term priority even though exploitation has not yet been confirmed.
| HPE Insight Remote Support | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
- Vendors
- hpe
- Products
- insight remote support
- Weakness
- CWE-91, CWE-611
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.