First published: Wed Jul 28 2021(Updated: )
Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Data Protection Advisor | =6.4 | |
Dell EMC Data Protection Advisor | =6.5 | |
Dell EMC Data Protection Advisor | =18.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Dell EMC Data Protection Advisor is CVE-2020-5351.
The severity of CVE-2020-5351 is high, with a severity value of 7.5.
Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 are affected by CVE-2020-5351.
CVE-2020-5351 allows a remote unauthenticated malicious user to gain read-only privileges by exploiting an undocumented account with a hard-coded password.
To fix CVE-2020-5351, it is recommended to upgrade to a patched version of Dell EMC Data Protection Advisor.