CVE-2022-45102

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/02/2023
Last modified:
07/11/2023

Description

<br /> Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger redirections.<br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_data_protection_central:*:*:*:*:*:*:*:* 19.1 (including) 19.8 (excluding)
cpe:2.3:o:dell:dp4400_firmware:*:*:*:*:*:*:*:* 2.5 (including) 2.7 (including)
cpe:2.3:h:dell:dp4400:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dp5900_firmware:*:*:*:*:*:*:*:* 2.5 (including) 2.7 (including)
cpe:2.3:h:dell:dp5900:-:*:*:*:*:*:*:*