CVE-2019-3754
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe3200 versions prior to 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.
Dell EMC Unity Operating Environment en versiones anteriores a la 5.0.0.0.5.116, Dell EMC UnityVSA en versiones anteriores a la 5.0.0.0.5.116 y Dell EMC VNXe3200 en versiones anteriores a la 3.1.10.9946299 contienen una vulnerabilidad de Cross-Site Scripting (XSS) reflejado en la página cas/logout. Un atacante remoto no identificado podría potencialmente aprovechar esta vulnerabilidad engañando a un usuario de una aplicación víctima para que proporcione código HTML o JavaScript malicioso a Unisphere, que se devuelve a la víctima y es ejecutado por el navegador web.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-09-03 CVE Published
- 2023-03-07 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Emc Vnxe3200 Firmware Search vendor "Dell" for product "Emc Vnxe3200 Firmware" | < 3.1.10.9946299 Search vendor "Dell" for product "Emc Vnxe3200 Firmware" and version " < 3.1.10.9946299" | - |
Affected
| in | Dell Search vendor "Dell" | Emc Vnxe3200 Search vendor "Dell" for product "Emc Vnxe3200" | - | - |
Safe
|
Dell Search vendor "Dell" | Emc Unity Operating Environment Search vendor "Dell" for product "Emc Unity Operating Environment" | < 5.0.0.0.5.116 Search vendor "Dell" for product "Emc Unity Operating Environment" and version " < 5.0.0.0.5.116" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Unityvsa Operating Environment Search vendor "Dell" for product "Emc Unityvsa Operating Environment" | < 5.0.0.0.5.116 Search vendor "Dell" for product "Emc Unityvsa Operating Environment" and version " < 5.0.0.0.5.116" | - |
Affected
|