CVE-2020-35170
Last modified
CVE-2020-35170 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users’ sessions.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, and Dell EMC PowerMax OS 5978.221.221 and 5978.479.479 contain a Cross-Site Scripting (XSS) vulnerability. An authenticated malicious user may potentially exploit this vulnerability to inject javascript code and affect other authenticated users’ sessions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Unisphere | < 9.1.0.24 |
| Dell | Unisphere | >= 9.2, < 9.2.0.6 |
| Dell | Powermax Os | 5978.221.221 |
| Dell | Powermax Os | 5978.479.479 |
References
- https://www.dell.com/support/kbdoc/000181212Vendor Advisory
- https://www.dell.com/support/kbdoc/000181212Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-35170?
How severe is CVE-2020-35170?
How do I fix CVE-2020-35170?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-35165Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, an…4.7
- CVE-2020-35166Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, an…9.8
- CVE-2020-35167Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, an…9.8
- CVE-2020-35168Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, an…9.8
- CVE-2020-35169Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, an…9.8
- CVE-2020-3517A vulnerability in the Cisco Fabric Services component of Ci…8.6
- CVE-2020-35173The Amaze File Manager application before 3.4.2 for Android …9.8
- CVE-2020-35175Frappe Framework 12 and 13 does not properly validate the HT…5.3
- CVE-2020-35176In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a…5.3
- CVE-2020-35177HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed…5.3
- CVE-2020-3518A vulnerability in the web-based management interface of Cis…5.4
- CVE-2020-35184The official composer docker images before 1.8.3 contain a b…9.8
Are you affected by CVE-2020-35170?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
