CVE-2020-5350: OS Command Injection
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5350?
CVE-2020-5350 has a severity rating of high, indicating a significant risk to affected systems.
How do I fix CVE-2020-5350?
To mitigate CVE-2020-5350, users should upgrade to a patched version of the Dell EMC Integrated Data Protection Appliance beyond 2.4.
What versions are affected by CVE-2020-5350?
CVE-2020-5350 affects Dell EMC Integrated Data Protection Appliance versions 2.0 through 2.4.
Can CVE-2020-5350 be exploited remotely?
Yes, CVE-2020-5350 can be exploited by a remote authenticated malicious user with root privileges.
What could an attacker achieve by exploiting CVE-2020-5350?
An attacker exploiting CVE-2020-5350 could manipulate passwords and potentially gain unauthorized access to sensitive data.