CVE-2024-0157: Medium severity dell storage resource manager vulnerability
Published Apr 12, 2024
·Updated
Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session.
Affected Software
3 affected components
Dell Storage Resource Manager<4.9.0.0
Dell Storage Monitoring And Reporting<5.0.0.0
Dell Storage Resource Manager<5.0.0.0
Event History
Apr 12, 2024
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0157?
The severity of CVE-2024-0157 is considered high due to its potential for session hijacking.
2
How do I fix CVE-2024-0157?
To fix CVE-2024-0157, update Dell Storage Resource Manager to version 4.9.0.1 or later.
3
Who can exploit CVE-2024-0157?
CVE-2024-0157 can be exploited by an unauthenticated attacker on an adjacent network.
4
What are the affected versions of Dell Storage Resource Manager for CVE-2024-0157?
The affected versions of Dell Storage Resource Manager for CVE-2024-0157 are 4.9.0.0 and below.
5
What is the impact of CVE-2024-0157?
The impact of CVE-2024-0157 is the potential hijacking of a targeted user's application session.