VYPR
Unrated severityNVD Advisory· Published Feb 12, 2024· Updated Aug 19, 2024

CVE-2024-22230

CVE-2024-22230

Description

Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the affected user or carry out any actions that this user could perform, or to generally control the victim's browser.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Unity versions before 5.4 contain a stored cross-site scripting vulnerability that allows an authenticated attacker to steal sessions or perform actions as the victim.

Vulnerability

Dell Unity, Dell Unity VSA, and Dell Unity XT versions prior to 5.4 contain a cross-site scripting (XSS) vulnerability in an unspecified web interface component. The vulnerability requires an authenticated attacker to inject malicious scripts into fields that are later rendered to other users without proper sanitization [1]. Affected software includes all Dell Unity family products running versions before 5.4 [1].

Exploitation

An attacker must first authenticate to the Dell Unity management interface. The attacker then injects crafted script payloads into input fields (such as configuration parameters or storage object names) that are viewable by other users. When a victim user (e.g., an administrator) views the affected page, the injected script executes in their browser context. No additional user interaction beyond viewing the page is required [1].

Impact

Successful exploitation enables the attacker to steal session cookies, perform actions as the victim (masquerading), or control the victim's browser. This can lead to unauthorized access to the management interface with the victim's privileges, potentially resulting in further compromise of the storage system [1].

Mitigation

Dell has released fixed firmware version 5.4, which resolves this vulnerability. Customers should upgrade to Unity OE version 5.4 or later as specified in Dell Security Advisory DSA-2024-042 [1]. No workarounds are documented; Dell recommends applying the update as soon as possible.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.