First published: Fri Mar 06 2020(Updated: )
Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Security Management Server | <10.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5327 is a vulnerability found in Dell Security Management Server versions prior to 10.2.10.
CVE-2020-5327 has a severity rating of 9.8 (Critical).
CVE-2020-5327 allows remote unauthenticated attackers to exploit a Java RMI Deserialization vulnerability on Dell Security Management Server versions prior to 10.2.10.
An attacker can exploit CVE-2020-5327 by sending a crafted RMI request to the server when it is exposed to the internet and Windows Firewall is disabled.
To fix CVE-2020-5327, it is recommended to update Dell Security Management Server to version 10.2.10 or later.