High severity7.2NVD Advisory· Published Mar 1, 2021· Updated Jun 17, 2026
CVE-2021-21517
CVE-2021-21517
Description
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:dell:emc_srs_policy_manager:6.6:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:dell:emc_srs_policy_manager:6.6:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_srs_policy_manager:6.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_srs_policy_manager:6.9.0:*:*:*:*:*:*:*
- Range: 6.X
- Range: unspecified
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.