9
CVSSv2

CVE-2020-5350

Published: 15/04/2020 Updated: 23/04/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc integrated data protection appliance 2.0

dell emc integrated data protection appliance 2.1

dell emc integrated data protection appliance 2.2

dell emc integrated data protection appliance 2.3

dell emc integrated data protection appliance 2.4