Description


Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.

Related CPE's


Weaknesses



CWE-345


CWE-345

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-07-12T14:15:08.593Z

4 years ago

Last modified

2024-11-21T04:48:39.423Z

1 year ago