Cross-Site WebSocket Hijacking in Dell EMC PowerFlex Presentation Server
CVE-2021-21588

6.5MEDIUM

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
12 July 2021

What is CVE-2021-21588?

The Dell EMC PowerFlex version 3.5.x is impacted by a Cross-Site WebSocket Hijacking vulnerability in its Presentation Server/WebUI. This flaw enables an unauthenticated adversary to exploit the system by deceiving the user into executing unwanted actions. Such actions could lead to unauthorized configuration changes, which poses significant security risks to the affected environment. It is crucial for users to be aware of potential exploits and take necessary precautions to safeguard their systems.

Affected Version(s)

PowerFlex 3.5.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.