CVE-2024-22229

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:unity_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unity_xt_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unityvsa_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*

History

21 Nov 2024, 08:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 3.1
References () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory

30 Jan 2024, 23:01

Type Values Removed Values Added
CPE cpe:2.3:a:dell:unity_xt_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unityvsa_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
cpe:2.3:a:dell:unity_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:*
First Time Dell
Dell unity Operating Environment
Dell unityvsa Operating Environment
Dell unity Xt Operating Environment
References () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory
CWE CWE-116
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

24 Jan 2024, 18:45

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-24 17:15

Updated : 2024-11-21 08:55


NVD link : CVE-2024-22229

Mitre link : CVE-2024-22229

CVE.ORG link : CVE-2024-22229


JSON object : View

Products Affected

dell

  • unityvsa_operating_environment
  • unity_xt_operating_environment
  • unity_operating_environment
CWE
CWE-117

Improper Output Neutralization for Logs

CWE-116

Improper Encoding or Escaping of Output