Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0130


Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access.


Published

2019-06-13T16:29:00.403

Last Modified

2024-11-21T04:16:17.970

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application intel rapid_storage_technology_enterprise < 5.5.0.2015 Yes
Operating System lenovo thinkstation_p520_firmware - Yes
Hardware lenovo thinkstation_p520 - No
Operating System lenovo thinkstation_p520c_firmware - Yes
Hardware lenovo thinkstation_p520c - No
Operating System lenovo thinkstation_p720_firmware - Yes
Hardware lenovo thinkstation_p720 - No
Operating System lenovo thinkstation_p920_firmware - Yes
Hardware lenovo thinkstation_p920 - No

References