Cross-site Scripting Vulnerability in Dell Storage Manager
CVE-2025-23379
5.2MEDIUM
Key Information:
- Vendor
Dell
- Vendor
- CVE Published:
- 6 May 2025
What is CVE-2025-23379?
Dell Storage Manager, particularly version 21.0.20, is susceptible to a cross-site scripting vulnerability due to improper input handling during web page generation. This flaw can be exploited by unauthenticated attackers who have adjacent network access, potentially leading to unauthorized script injection activities. Such vulnerabilities underscore the importance of securing web applications against malicious inputs and maintaining up-to-date software to mitigate risks.
Affected Version(s)
Dell Storage Center - Dell Storage Manager < 2020 R1.21
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell would like to thank redfr0g for reporting this issue.