Home
MEDIUM: 5.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:LDefault status
unaffected
Any version before 4.3.0.0 or later
affected
Default status
unaffected
Any version before 4.3.0.0 or later
affected
Description
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in a CSV File vulnerability in the UI. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
Problem types
CWE-1236: Improper Neutralization of Formula Elements in a CSV File
Product status
Any version before 4.3.0.0 or later
Any version before 4.3.0.0 or later
References
www.dell.com/...s-and-objectscale-multiple-vulnerabilities-1