CVE-2024-22229

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:unity_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unity_xt_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unityvsa_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*

History

30 Jan 2024, 23:01

Type Values Removed Values Added
First Time Dell
Dell unity Operating Environment
Dell unityvsa Operating Environment
Dell unity Xt Operating Environment
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:dell:unity_xt_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unityvsa_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unity_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
CWE CWE-116
References () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory

24 Jan 2024, 18:45

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-24 17:15

Updated : 2024-02-28 20:54


NVD link : CVE-2024-22229

Mitre link : CVE-2024-22229

CVE.ORG link : CVE-2024-22229


JSON object : View

Products Affected

dell

  • unity_xt_operating_environment
  • unityvsa_operating_environment
  • unity_operating_environment
CWE
CWE-116

Improper Encoding or Escaping of Output

CWE-117

Improper Output Neutralization for Logs