Description

Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote authenticated attacker could potentially exploit these issues, leading to various injection type attacks.

Published: 2023-10-05
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-47492 Dell SmartFabric Storage Software v1.4 (and earlier) contains possible vulnerabilities for HTML injection or CVS formula injection which might escalate to cross-site scripting attacks in HTML pages in the GUI. A remote authenticated attacker could potentially exploit these issues, leading to various injection type attacks.
History

Thu, 19 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Dell Smartfabric Storage Software
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-19T18:48:48.616Z

Reserved: 2023-09-15T07:00:32.006Z

Link: CVE-2023-43071

cve-icon Vulnrichment

Updated: 2024-08-02T19:37:23.000Z

cve-icon NVD

Status : Modified

Published: 2023-10-05T18:15:12.347

Modified: 2024-11-21T08:23:40.637

Link: CVE-2023-43071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses