CVE-2019-18588

MEDIUM

Dell EMC Unisphere for PowerMax <9.1.0.9, <9.0.2.16 & 5978.221.221,...

Title source: llm
STIX 2.1

Description

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users' sessions.

Scores

CVSS v3 5.4
EPSS 0.0044
EPSS Percentile 63.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
dell/emc_powermax 5978.221.221
dell/emc_powermax 5978.479.479
dell/emc_unisphere_for_powermax < 9.0.2.16
Published Jan 10, 2020
Tracked Since Feb 18, 2026