CVE-2020-29490: High severity dell emc unity xt operating environment vulnerability
Published Jan 5, 2021
·Updated
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A remote authenticated attacker could potentially exploit this vulnerability and cause Denial of Service (Storage Processor Panic) by sending specially crafted UDP requests.
Affected Software
3 affected components
Dell EMC Unity Operating Environment<5.0.4.0.5.012
Dell Emc Unity Vsa Operating Environment<5.0.4.0.5.012
Dell Emc Unity Xt Operating Environment<5.0.4.0.5.012
Event History
Jan 5, 2021
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-29490?
The severity of CVE-2020-29490 is rated as high with a CVSS score of 6.5.
2
How can an attacker exploit CVE-2020-29490 vulnerability?
A remote authenticated attacker could potentially exploit CVE-2020-29490 by sending specially crafted packets to cause Denial of Service (Storage Processor Panic).
3
Is there a fix available for CVE-2020-29490?
Yes, updating Dell EMC Unity, Unity XT, and UnityVSA to version 5.0.4.0.5.012 or higher fixes the vulnerability.