6.1
CVSSv3

CVE-2019-3754

Published: 03/09/2019 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Dell EMC Unity Operating Environment versions before 5.0.0.0.5.116, Dell EMC UnityVSA versions before 5.0.0.0.5.116 and Dell EMC VNXe3200 versions before 3.1.10.9946299 contain a reflected cross-site scripting vulnerability on the cas/logout page. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc unityvsa operating environment

dell emc unity operating environment

dell emc_vnxe3200_firmware