Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/108775 | Broken Link Third Party Advisory VDB Entry |
https://support.lenovo.com/us/en/product_security/LEN-27843 | Third Party Advisory |
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00226.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
02 Mar 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | (CONFIRM) https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00226.html - Patch, Vendor Advisory | |
References | (CONFIRM) https://support.lenovo.com/us/en/product_security/LEN-27843 - Third Party Advisory | |
References | (BID) http://www.securityfocus.com/bid/108775 - Broken Link, Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:o:lenovo:thinkstation_p520_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p520c_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p520c:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p920:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p720:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p920_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:lenovo:thinkstation_p520:-:*:*:*:*:*:*:* cpe:2.3:o:lenovo:thinkstation_p720_firmware:-:*:*:*:*:*:*:* |
Information
Published : 2019-06-13 16:29
Updated : 2024-02-04 20:20
NVD link : CVE-2019-0130
Mitre link : CVE-2019-0130
CVE.ORG link : CVE-2019-0130
JSON object : View
Products Affected
lenovo
- thinkstation_p520_firmware
- thinkstation_p920
- thinkstation_p520c
- thinkstation_p920_firmware
- thinkstation_p720
- thinkstation_p720_firmware
- thinkstation_p520
- thinkstation_p520c_firmware
intel
- rapid_storage_technology_enterprise
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')