CVE-2021-21588

Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An unauthenticated attacker could potentially exploit this vulnerability by tricking the user into performing unwanted actions on the Presentation Server and perform which may lead to configuration changes.
References
Link Resource
https://www.dell.com/support/kbdoc/000189265 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:powerflex_presentation_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-07-12 16:15

Updated : 2024-02-28 18:28


NVD link : CVE-2021-21588

Mitre link : CVE-2021-21588

CVE.ORG link : CVE-2021-21588


JSON object : View

Products Affected

dell

  • powerflex_presentation_server
CWE
CWE-345

Insufficient Verification of Data Authenticity