PT-2024-2895 · Dell · Dell Unity
Published
2024-02-12
·
Updated
2024-08-14
·
CVE-2024-0169
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell Unity versions prior to 5.4
Description
The issue is related to an Improper Neutralization of Input During Web Page Generation, also known as a Cross-site Scripting (XSS) vulnerability. This could allow a low-privileged attacker with remote access to potentially exploit the vulnerability, leading to information exposure. An authenticated attacker could exploit this vulnerability, potentially leading users to download and execute malicious software, compromising their systems.
Recommendations
For versions prior to 5.4, update to version 5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface of Dell Unity to minimize the risk of exploitation. Avoid using the vulnerable web page generation feature until the issue is resolved.
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Unity