ZeroHour

CVE-2021-21588

CVSS 3.1
4.3 medium
EPSS
<1%p27
Published
()
Modified
Description

Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.

Vendors
dell
Products
powerflex presentation server
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.