CVE-2024-38485: Dell Elastic Cloud Storage

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.

Affected products

  • Dell Elastic Cloud Storage: before 3.8.0.0 (fixed in 3.8.0.0)

Published 2024-12-09. Last modified 2026-06-17.