CVE-2024-0157

Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:storage_monitoring_and_reporting:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_resource_manager:*:*:*:*:*:*:*:*

History

04 Feb 2025, 17:08

Type Values Removed Values Added
CWE CWE-384
CPE cpe:2.3:a:dell:storage_monitoring_and_reporting:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:storage_resource_manager:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-nz/000224070/dsa-2024-143-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-nz/000224070/dsa-2024-143-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities - Vendor Advisory
First Time Dell storage Monitoring And Reporting
Dell storage Resource Manager
Dell

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-nz/000224070/dsa-2024-143-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-nz/000224070/dsa-2024-143-dell-storage-resource-manager-srm-and-dell-storage-monitoring-and-reporting-smr-security-update-for-multiple-third-party-component-vulnerabilities -

12 Apr 2024, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-12 17:17

Updated : 2025-02-04 17:08


NVD link : CVE-2024-0157

Mitre link : CVE-2024-0157

CVE.ORG link : CVE-2024-0157


JSON object : View

Products Affected

dell

  • storage_monitoring_and_reporting
  • storage_resource_manager
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-384

Session Fixation