CVE-2020-5345

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:emc_unisphere_for_powermax:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:*

History

21 Nov 2024, 05:33

Type Values Removed Values Added
CVSS v2 : 5.5
v3 : 5.4
v2 : 5.5
v3 : 6.4
References () https://www.dell.com/support/security/en-us/details/544585/DSA-2020-065-Dell-EMC-Unisphere-for-PowerMax-Dell-EMC-Unisphere-for-PowerMax-Virtual-ApplianceĀ - Vendor Advisory () https://www.dell.com/support/security/en-us/details/544585/DSA-2020-065-Dell-EMC-Unisphere-for-PowerMax-Dell-EMC-Unisphere-for-PowerMax-Virtual-ApplianceĀ - Vendor Advisory

Information

Published : 2020-06-23 20:15

Updated : 2024-11-21 05:33


NVD link : CVE-2020-5345

Mitre link : CVE-2020-5345

CVE.ORG link : CVE-2020-5345


JSON object : View

Products Affected

dell

  • emc_unisphere_for_powermax_virtual_appliance
  • emc_unisphere_for_powermax
  • powermax_os
CWE
CWE-602

Client-Side Enforcement of Server-Side Security

CWE-862

Missing Authorization