CVE-2017-14383: Dell Emc VNX1 Firmware

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In Dell EMC VNX2 versions prior to Operating Environment for File 8.1.9.217 and VNX1 versions prior to Operating Environment for File 7.1.80.8, a web server error page in VNX Control Station is impacted by a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary HTML code in the user's browser session in the context of the affected web application.

Affected products

  • Dell Emc VNX1 Firmware: before 7.1.80.8 (fixed in 7.1.80.8)
  • Dell Emc VNX2 Firmware: before 8.1.9.217 (fixed in 8.1.9.217)

Published 2018-01-04. Last modified 2026-06-17.