CVE-2020-5368

Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dell:vxrail_d560f_firmware:4.7.410:*:*:*:*:*:*:*
cpe:2.3:o:dell:vxrail_d560f_firmware:4.7.411:*:*:*:*:*:*:*
cpe:2.3:o:dell:vxrail_d560f_firmware:4.7.510:*:*:*:*:*:*:*
cpe:2.3:h:dell:vxrail_d560f:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:dell:vxrail_d560_firmware:4.7.410:*:*:*:*:*:*:*
cpe:2.3:o:dell:vxrail_d560_firmware:4.7.411:*:*:*:*:*:*:*
cpe:2.3:o:dell:vxrail_d560_firmware:4.7.510:*:*:*:*:*:*:*
cpe:2.3:h:dell:vxrail_d560:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:34

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 9.8
References () https://www.dell.com/support/security/en-us/details/544058/DSA-2020-136-Dell-EMC-VxRail-Appliance-Improper-Authentication-Vulnerability - Vendor Advisory () https://www.dell.com/support/security/en-us/details/544058/DSA-2020-136-Dell-EMC-VxRail-Appliance-Improper-Authentication-Vulnerability - Vendor Advisory

Information

Published : 2020-07-06 18:15

Updated : 2024-11-21 05:34


NVD link : CVE-2020-5368

Mitre link : CVE-2020-5368

CVE.ORG link : CVE-2020-5368


JSON object : View

Products Affected

dell

  • vxrail_d560f
  • vxrail_d560f_firmware
  • vxrail_d560
  • vxrail_d560_firmware
CWE
CWE-862

Missing Authorization