First published: Wed Sep 02 2020(Updated: )
Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Elastic Cloud Storage | <3.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5386 is classified as a medium severity vulnerability due to its exposure of sensitive data.
To remediate CVE-2020-5386, upgrade your Dell EMC ECS software to version 3.5 or later.
CVE-2020-5386 allows remote unauthenticated attackers to access sensitive information by listing Directory Table objects.
If you are running a version of Dell EMC ECS prior to 3.5, your system is vulnerable to CVE-2020-5386.
Organizations using Dell EMC Elastic Cloud Storage versions before 3.5 are affected by CVE-2020-5386.