HIGH🇵🇱 Wersja polska

CVE-2020-5372

CVSS 8.6v3.1pub. 2020-07-06upd. 2024-11-21

Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
  • Dell Emc Powerstore 1000

    HW
    Dell
    all versions
  • Dell Emc Powerstore 1000 Firmware

    OS
    Dell
    < 1.0.1.0.5.002
  • Dell Emc Powerstore 3000

    HW
    Dell
    all versions
  • Dell Emc Powerstore 3000 Firmware

    OS
    Dell
    < 1.0.1.0.5.002
  • Dell Emc Powerstore 5000

    HW
    Dell
    all versions
  • Dell Emc Powerstore 5000 Firmware

    OS
    Dell
    < 1.0.1.0.5.002
  • Dell Emc Powerstore 7000

    HW
    Dell
    all versions
  • Dell Emc Powerstore 7000 Firmware

    OS
    Dell
    < 1.0.1.0.5.002
  • Dell Emc Powerstore 9000

    HW
    Dell
    all versions
  • Dell Emc Powerstore 9000 Firmware

    OS
    Dell
    < 1.0.1.0.5.002
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDoS
CWE
References

Related vulnerabilities

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-54489CRITICAL9.1PL ✓same vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta

CVE-2026-67261CRITICAL9.8PL ✓same vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)

CVE-2026-40712CRITICAL9.1PL ✓same vendor

Dell PowerProtect Data Manager – Improper Input Validation w REST API (Privilege Escalation)

CVE-2026-46738CRITICAL9.1PL ✓same vendor

Dell PowerProtect Data Manager – Improper Input Validation w REST API (privilege escalation)