CVE-2020-5386: High severity dell emc elastic cloud storage vulnerability
Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5386?
CVE-2020-5386 is classified as a medium severity vulnerability due to its exposure of sensitive data.
How do I fix CVE-2020-5386?
To remediate CVE-2020-5386, upgrade your Dell EMC ECS software to version 3.5 or later.
What impact does CVE-2020-5386 have on my system?
CVE-2020-5386 allows remote unauthenticated attackers to access sensitive information by listing Directory Table objects.
Is my system vulnerable to CVE-2020-5386?
If you are running a version of Dell EMC ECS prior to 3.5, your system is vulnerable to CVE-2020-5386.
Who is affected by CVE-2020-5386?
Organizations using Dell EMC Elastic Cloud Storage versions before 3.5 are affected by CVE-2020-5386.