CVE-2024-30476: XSS
PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the PowerStore Manager management interface to trusted IPs/networks (firewall, ACL, VPN) so only authorized administrators can reach the interface, reducing exposure to remote authenticated attackers.
- Operational
Audit and tighten user accounts and privileges for PowerStore Manager: remove or disable unneeded low-privileged accounts, review recent administrative/logins for suspicious activity, and monitor client-side activity for signs of stored XSS exploitation until a vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30476?
The severity of CVE-2024-30476 is rated as medium with a score of 5.4.
How do I fix CVE-2024-30476?
To fix CVE-2024-30476, you should apply the recommended security updates from Dell EMC for PowerStore Manager.
What type of vulnerability is CVE-2024-30476?
CVE-2024-30476 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who can exploit CVE-2024-30476?
CVE-2024-30476 can be exploited by a remote authenticated low-privileged malicious actor.
What could happen if CVE-2024-30476 is exploited?
If exploited, CVE-2024-30476 could lead to script execution in the client browser.