First published: Tue Jul 07 2020(Updated: )
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Idrac9 Firmware | <4.20.20.20 | |
Dell iDRAC9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5366 refers to a Path Traversal Vulnerability in Dell EMC iDRAC9 versions prior to 4.20.20.20.
CVE-2020-5366 allows a remote authenticated malicious user with low privileges to gain unauthorized read access to arbitrary files by manipulating input parameters.
CVE-2020-5366 has a severity rating of 6.5 (High).
To fix CVE-2020-5366, Dell EMC iDRAC9 users should update to version 4.20.20.20 or later.
More information about CVE-2020-5366 can be found at the following link: [https://www.dell.com/support/article/en-us/sln322125/dsa-2020-128-idrac-local-file-inclusion-vulnerability?lang=en](https://www.dell.com/support/article/en-us/sln322125/dsa-2020-128-idrac-local-file-inclusion-vulnerability?lang=en)