CVE-2020-5366: Path Traversal
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5366?
CVE-2020-5366 refers to a Path Traversal Vulnerability in Dell EMC iDRAC9 versions prior to 4.20.20.20.
How does CVE-2020-5366 affect Dell EMC iDRAC9?
CVE-2020-5366 allows a remote authenticated malicious user with low privileges to gain unauthorized read access to arbitrary files by manipulating input parameters.
What is the severity of CVE-2020-5366?
CVE-2020-5366 has a severity rating of 6.5 (High).
How can I fix CVE-2020-5366?
To fix CVE-2020-5366, Dell EMC iDRAC9 users should update to version 4.20.20.20 or later.
Where can I find more information about CVE-2020-5366?
More information about CVE-2020-5366 can be found at the following link: [https://www.dell.com/support/article/en-us/sln322125/dsa-2020-128-idrac-local-file-inclusion-vulnerability?lang=en](https://www.dell.com/support/article/en-us/sln322125/dsa-2020-128-idrac-local-file-inclusion-vulnerability?lang=en)