Vulnerability Description
Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browser to desynchronize its connection with the website, typically leading to XSS and DoS.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powervault Me5012 Firmware | < me5.1.1.0.5 |
| Dell | Powervault Me5012 | - |
| Dell | Powervault Me5024 Firmware | < me5.1.1.0.5 |
| Dell | Powervault Me5024 | - |
| Dell | Powervault Me5084 Firmware | < me5.1.1.0.5 |
| Dell | Powervault Me5084 | - |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/kbdoc/en-us/000207533/dsa-2023-018-dell-emc-powervaVendor Advisory
- https://www.dell.com/support/kbdoc/en-us/000207533/dsa-2023-018-dell-emc-powervaVendor Advisory
FAQ
What is CVE-2023-23691?
CVE-2023-23691 is a vulnerability with a CVSS score of 8.1 (HIGH). Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browse...
How severe is CVE-2023-23691?
CVE-2023-23691 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23691?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Powervault Me5012 Firmware, Dell Powervault Me5012, Dell Powervault Me5024 Firmware, Dell Powervault Me5024, Dell Powervault Me5084 Firmware.