CVE-2020-29499: OS Command Injection
Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29499?
The severity of CVE-2020-29499 is high, with a CVSS score of 6.7.
What is the affected software for CVE-2020-29499?
Dell EMC PowerStore versions prior to 1.0.3.0.5.006 are affected by CVE-2020-29499.
How can an attacker exploit CVE-2020-29499?
A locally authenticated attacker could potentially exploit CVE-2020-29499 by executing arbitrary OS commands on the PowerStore underlying OS.
Is there a fix available for CVE-2020-29499?
Yes, it is recommended to update to Dell EMC PowerStore version 1.0.3.0.5.006 or later to fix CVE-2020-29499.
Where can I find more information about CVE-2020-29499?
You can find more information about CVE-2020-29499 in the Dell EMC PowerStore support knowledge base article at https://www.dell.com/support/kbdoc/000180775.