Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
CVE ID: CVE-2024-38485
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
Vendor: Dell
Product: ECS
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 28.06% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)