First published: Thu Dec 14 2023(Updated: )
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or JavaScript code to a victim user's DOM environment in the browser. . Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Dell PowerProtect Data Protection | <2.7.6 | |
Any of | ||
Dell DP4400 | ||
Dell DP5900 Firmware | ||
All of | ||
Any of | ||
Dell Apex Protection Storage | <6.2.1.110 | |
Dell Apex Protection Storage | >=7.0<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.12.0.0 | |
Dell PowerProtect Data Domain Management Center | <6.2.1.110 | |
Dell PowerProtect Data Domain Management Center | >=7.0<7.13.0.10 | |
EMC Data Domain Operating System | <6.2.1.110 | |
EMC Data Domain Operating System | >=7.0<7.12.0.0 | |
EMC Data Domain Operating System | >=7.7<7.7.5.25 | |
EMC Data Domain Operating System | >=7.10<7.10.1.15 | |
Dell PowerProtect Data Domain Management Center | >=7.7<7.7.5.25 | |
Dell PowerProtect Data Domain Management Center | >=7.10<7.10.1.15 | |
Any of | ||
Dell DD3300 | ||
Dell DD6400 | ||
Dell DD6900 | ||
Dell DD9400 | ||
Dell Dd9900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-44286 is classified as a high severity DOM-based Cross-Site Scripting vulnerability.
To fix CVE-2023-44286, update Dell PowerProtect DD and related products to the versions 7.13.0.10 or later, LTS 7.7.5.25, or LTS 7.10.1.15.
CVE-2023-44286 affects users of Dell PowerProtect DD prior to 7.13.0.10 and multiple Dell products below specified versions.
CVE-2023-44286 could enable remote unauthenticated attackers to inject malicious HTML or JavaScript code.
No, CVE-2023-44286 can be exploited by remote unauthenticated attackers.