PT-2024-2895 · Dell · Dell Unity

Published

2024-02-12

·

Updated

2024-08-14

·

CVE-2024-0169

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell Unity versions prior to 5.4
Description The issue is related to an Improper Neutralization of Input During Web Page Generation, also known as a Cross-site Scripting (XSS) vulnerability. This could allow a low-privileged attacker with remote access to potentially exploit the vulnerability, leading to information exposure. An authenticated attacker could exploit this vulnerability, potentially leading users to download and execute malicious software, compromising their systems.
Recommendations For versions prior to 5.4, update to version 5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface of Dell Unity to minimize the risk of exploitation. Avoid using the vulnerable web page generation feature until the issue is resolved.

Fix

XSS

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-03060
CVE-2024-0169

Affected Products

Dell Unity