DSA-2025-277: Security Update for Dell AppSync Vulnerabilities
Summary: Dell AppSync remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Medium
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-36603 | Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | 4.2 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L |
| CVE-2025-32744 | Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | 6.6 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-36603 | Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | 4.2 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L |
| CVE-2025-32744 | Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | 6.6 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Affected Products & Remediation
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell AppSync | AppSync | Versions prior to 4.6.0.4 | Version 4.6.0.4 or later | https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| Dell AppSync | AppSync | Versions prior to 4.6.0.4 | Version 4.6.0.4 or later | https://dl.dell.com/downloads/JD3VM_AppSync-4.6.0.4-(Build-number-4.6.0.4-74)-Software.zip |
Revision History
| Revision | Date | Description |
| 1.0 | 2025-07-15 | Initial Release |
| 2.0 | 2025-07-15 | Updated the CVE details |
Acknowledgements
CVE-2025-36603: Dell would like to thank Ouallaout Noureddine for reporting this issue
CVE-2025-32744: Dell would like to thank Ahmed Y. Elmogy for reporting this issue
Related Information
Legal Disclaimer
Affected Products
AppSync, AppSyncArticle Properties
Article Number: 000345331
Article Type: Dell Security Advisory
Last Modified: 15 Jul 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.