CVE-2023-23691: Dell Powervault ME5012 Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Dell EMC PV ME5, versions ME5.1.0.0.0 and ME5.1.0.1.0, contains a Client-side desync Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability to force a victim's browser to desynchronize its connection with the website, typically leading to XSS and DoS.

Affected products

  • Dell Powervault ME5012 Firmware: before me5.1.1.0.5 (fixed in me5.1.1.0.5)
  • Dell Powervault ME5024 Firmware: before me5.1.1.0.5 (fixed in me5.1.1.0.5)
  • Dell Powervault ME5084 Firmware: before me5.1.1.0.5 (fixed in me5.1.1.0.5)

Published 2023-01-20. Last modified 2026-06-17.