Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.
References
Configurations
Configuration 1 (hide)
|
History
30 Jan 2024, 23:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
First Time |
Dell unity Operating Environment
Dell unityvsa Operating Environment Dell unity Xt Operating Environment Dell |
|
CWE | CWE-116 | |
CPE | cpe:2.3:a:dell:unity_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:* cpe:2.3:a:dell:unity_xt_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:* cpe:2.3:a:dell:unityvsa_operating_environment:5.3.0.0.5.120:*:*:*:*:*:*:* |
|
References | () https://www.dell.com/support/kbdoc/en-us/000213152/dsa-2023-141-dell-unity-unity-vsa-and-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory |
24 Jan 2024, 18:45
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-24 17:15
Updated : 2024-01-30 23:01
NVD link : CVE-2024-22229
Mitre link : CVE-2024-22229
JSON object : View
Products Affected
dell
- unityvsa_operating_environment
- unity_xt_operating_environment
- unity_operating_environment
CWE
CWE-116
Improper Encoding or Escaping of Output