HIGH🇬🇧 English

CVE-2020-5366

CVSS 7.1v3.1pub. 2020-07-09upd. 2024-11-21

Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
  • Dell Idrac9

    HW
    Dell
    wszystkie wersje
  • Dell Idrac9 Firmware

    OS
    Dell
    < 4.20.20.20
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Path Traversal
CWE
Referencje

Powiązane podatności

CVE-2022-24422CRITICAL9.6PL ✓ten sam produkt

Dell iDRAC9 — ominięcie uwierzytelnienia w konsoli VNC (Auth Bypass)

CVE-2021-21538CRITICAL9.6PL ✓ten sam produkt

Auth Bypass w Dell EMC iDRAC9 — dostęp do wirtualnej konsoli

CVE-2019-3705CRITICAL9.8PL ✓ten sam produkt

Stack-based buffer overflow w Dell EMC iDRAC6/7/8/9 — zdalny RCE

CVE-2024-25943HIGH7.6ten sam produkt

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contai...

CVE-2020-5344HIGH7.0ten sam produkt

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based ...