EMC VNX1/VNX2 OE for File CVE-2017-14383 Unspecified Cross Site Scripting Vulnerability
BID:102273
Info
EMC VNX1/VNX2 OE for File CVE-2017-14383 Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 102273 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-14383 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2017 12:00AM |
| Updated: | Dec 19 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
EMC VNX2 OE for File 8.1.9.211 EMC VNX2 OE for File 8.1.9.155 EMC VNX1 OE for File 7.1.79.6 |
| Not Vulnerable: |
EMC VNX2 OE for File 8.1.9.217 EMC VNX1 OE for File 7.1.80.8 |
Discussion
EMC VNX1/VNX2 OE for File CVE-2017-14383 Unspecified Cross Site Scripting Vulnerability
EMC VNX1/VNX2 OE for File are prone to an unspecified cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to VNX2 OE for File 8.1.9.217 and VNX1 OE for File 7.1.80.8 are vulnerable.
EMC VNX1/VNX2 OE for File are prone to an unspecified cross-site scripting vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Versions prior to VNX2 OE for File 8.1.9.217 and VNX1 OE for File 7.1.80.8 are vulnerable.
Exploit / POC
EMC VNX1/VNX2 OE for File CVE-2017-14383 Unspecified Cross Site Scripting Vulnerability
An attacker can exploit these issues by enticing an unsuspecting user to visit a specially crafted URL.
An attacker can exploit these issues by enticing an unsuspecting user to visit a specially crafted URL.
Solution / Fix
EMC VNX1/VNX2 OE for File CVE-2017-14383 Unspecified Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EMC VNX1/VNX2 OE for File CVE-2017-14383 Unspecified Cross Site Scripting Vulnerability
References:
References: