CVE-2020-5351: High severity emc data protection advisor collector vulnerability
Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Dell EMC Data Protection Advisor?
The vulnerability ID for Dell EMC Data Protection Advisor is CVE-2020-5351.
What is the severity of CVE-2020-5351?
The severity of CVE-2020-5351 is high, with a severity value of 7.5.
Which versions of Dell EMC Data Protection Advisor are affected by CVE-2020-5351?
Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 are affected by CVE-2020-5351.
What is the impact of CVE-2020-5351?
CVE-2020-5351 allows a remote unauthenticated malicious user to gain read-only privileges by exploiting an undocumented account with a hard-coded password.
How can I fix CVE-2020-5351?
To fix CVE-2020-5351, it is recommended to upgrade to a patched version of Dell EMC Data Protection Advisor.