Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.
2018-09-28T18:29:01.083
2024-11-21T03:59:28.067
Modified
CVSSv3.0: 8.3 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dell | emc_unity_firmware | < 4.3.1.1525703027 | Yes |
Hardware | dell | emc_unity | - | No |
Operating System | dell | emc_unityvsa | < 4.3.1.1525703027 | Yes |