CVE-2021-21588

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
12/07/2021
Last modified:
14/07/2021

Description

Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:powerflex_presentation_server:*:*:*:*:*:*:*:* 3.5 (including) 3.6 (excluding)


References to Advisories, Solutions, and Tools