DSA-2021-138: Dell PowerFlex Security Update for a Cross-Site WebSocket Hijacking in WebUI/Presentation Server Vulnerability

Oversigt: Dell PowerFlex remediation is available for the Presentation Server that could be exploited by malicious users to compromise the affected system.

Denne artikel gælder for Denne artikel gælder ikke for Denne artikel er ikke knyttet til et bestemt produkt. Det er ikke alle produktversioner, der er identificeret i denne artikel.

Virkning

Medium

Oplysninger

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21588 Dell PowerFlex versions 3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker may potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server which may lead to configuration changes. 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2021-21588 Dell PowerFlex versions 3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker may potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server which may lead to configuration changes. 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Dell Technologies anbefaler, at alle kunder tager hensyn til både CVSS-basisresultatet og alle relevante tidsmæssige og miljømæssige resultater, som kan have betydning for den potentielle alvorsgrad, der er forbundet med en bestemt sikkerhedsrisiko.

Berørte produkter og udbedring

Product Affected Versions Updated Version Link to Update
PowerFlex Presentation Server
 
 3.5.x 3.6 https://dl.dell.com/downloads/DL104415_PowerFlex-3.6-Build-355-Complete-Software-Download.zip
Product Affected Versions Updated Version Link to Update
PowerFlex Presentation Server
 
 3.5.x 3.6 https://dl.dell.com/downloads/DL104415_PowerFlex-3.6-Build-355-Complete-Software-Download.zip

Revisionshistorik

RevisionDateDescription
1.02021-07-01Initial Release

Relaterede oplysninger

Berørte produkter

Product Security Information
Artikelegenskaber
Artikelnummer: 000189265
Artikeltype: Dell Security Advisory
Senest ændret: 01 jul. 2021
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.