Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
History

Tue, 13 May 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell storage Manager
CPEs cpe:2.3:a:dell:storage_manager:16.3.20:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2016:r2.1:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.10:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.20:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1.2:*:*:*:*:*:*
cpe:2.3:a:dell:storage_manager:2020:r1:*:*:*:*:*:*
Vendors & Products Dell
Dell storage Manager

Tue, 06 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 May 2025 15:45:00 +0000

Type Values Removed Values Added
Description Dell Storage Center - Dell Storage Manager, version(s) 21.0.20, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2025-05-06T15:45:22.220Z

Reserved: 2025-01-15T06:04:03.642Z

Link: CVE-2025-23379

cve-icon Vulnrichment

Updated: 2025-05-06T15:45:13.241Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-06T16:15:27.557

Modified: 2025-05-13T20:18:55.637

Link: CVE-2025-23379

cve-icon Redhat

No data.