CVE-2022-45102Improper Neutralization of HTTP Headers for Scripting Syntax in Dell EMC Data Protection Central

Severity
6.1MEDIUMNVD
CNA5.4
EPSS
0.4%
top 36.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1

Description

Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger redirections.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5dell/data_protection_central19.119.7
NVDdell/dp4400_firmware2.52.7
NVDdell/dp5900_firmware2.52.7

🔴Vulnerability Details

2
CVEList
CVE-2022-45102: Dell EMC Data Protection Central, versions 192023-02-01
GHSA
GHSA-vhfp-p9xr-gg6w: Dell EMC Data Protection Central, versions 192023-02-01
CVE-2022-45102 — Dell vulnerability | cvebase