First published: Mon Jul 06 2020(Updated: )
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell PowerProtect Data Manager Dm5500 Firmware | <19.4 | |
Dell PowerProtect X400 Firmware | <3.2 | |
Dell PowerProtect |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5356 is classified as a medium-severity vulnerability that could allow unauthorized file downloads.
To mitigate CVE-2020-5356, upgrade Dell PowerProtect Data Manager to version 19.4 or later and Dell PowerProtect X400 to version 3.2 or later.
The risk of CVE-2020-5356 includes the potential for a remote authenticated attacker to access and download sensitive files from affected systems.
CVE-2020-5356 affects Dell PowerProtect Data Manager versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2.
Yes, CVE-2020-5356 involves an improper authorization vulnerability that can be exploited by remote authenticated users.