DSA-2020-016: Dell EMC ECS Cross-Site Scripting (XSS) Vulnerability

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Summary:   
Dell EMC ECS contains remediation for an XSS vulnerability that may potentially be exploited by malicious users to compromise the affected system.

  • Cross-Site Scripting (XSS) Vulnerability

CVE-2020-5317

Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code may get executed by the web browser in the context of the vulnerable web application.

CVSS v3.0 Base Score: 6.2 (AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N)

  • Cross-Site Scripting (XSS) Vulnerability

CVE-2020-5317

Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user may potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code may get executed by the web browser in the context of the vulnerable web application.

CVSS v3.0 Base Score: 6.2 (AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:N)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:  
Dell EMC ECS versions prior to 3.4.0.1

Remediation:
The following Dell EMC ECS release addresses this vulnerability:  

  • Dell EMC ECS 3.4.0.1

Dell EMC recommends all customers have their Dell EMC ECS systems upgraded at the earliest opportunity by opening a Dell EMC ECS service request.

Link to Request Upgrade:   
https://www.dell.com/support/home



Affected products:  
Dell EMC ECS versions prior to 3.4.0.1

Remediation:
The following Dell EMC ECS release addresses this vulnerability:  

  • Dell EMC ECS 3.4.0.1

Dell EMC recommends all customers have their Dell EMC ECS systems upgraded at the earliest opportunity by opening a Dell EMC ECS service request.

Link to Request Upgrade:   
https://www.dell.com/support/home



Acknowledgements

Dell would like to thank Ben Sazgar from Citadel Cyber Security for reporting this issue.

Related Information

Affected Products

Elastic Cloud Storage

Products

ECS Appliance, ECS Appliance Software with Encryption, ECS Appliance Software without Encryption, Elastic Cloud Storage, Product Security Information
Article Properties
Article Number: 000153909
Article Type: Dell Security Advisory
Last Modified: 20 Sep 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.