First published: Tue Sep 03 2019(Updated: )
Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Unity Operating Environment | <5.0.0.0.5.116 | |
Dell Emc Unityvsa Operating Environment | <5.0.0.0.5.116 | |
Dell Emc Vnxe3200 Firmware | <3.1.10.9946299 | |
Dell EMC VNXe3200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3754 is a reflected cross-site scripting vulnerability in Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116, and Dell EMC VNXe3200 versions prior to 3.1.10.9946299.
The severity of CVE-2019-3754 is medium with a CVSS score of 6.1.
CVE-2019-3754 affects Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116 by allowing a remote unauthenticated attacker to execute cross-site scripting attacks on the cas/logout page.
CVE-2019-3754 affects Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 by allowing a remote unauthenticated attacker to execute cross-site scripting attacks on the cas/logout page.
CVE-2019-3754 affects Dell EMC VNXe3200 versions prior to 3.1.10.9946299 by allowing a remote unauthenticated attacker to execute cross-site scripting attacks on the cas/logout page.