CVE-2020-5374

Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacker may exploit this vulnerability to gain access to the appliance data for remotely managed devices.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:emc_omimssc_for_sccm:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_omimssc_for_scvmm:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:34

Type Values Removed Values Added
References () https://www.dell.com/support/article/en-us/sln322169/dsa-2020-163-dell-emc-openmanage-integration-for-microsoft-system-center-multiple-vulnerabilities?lang=en - Vendor Advisory () https://www.dell.com/support/article/en-us/sln322169/dsa-2020-163-dell-emc-openmanage-integration-for-microsoft-system-center-multiple-vulnerabilities?lang=en - Vendor Advisory
CVSS v2 : 5.0
v3 : 7.5
v2 : 5.0
v3 : 8.8

Information

Published : 2020-07-14 20:15

Updated : 2024-11-21 05:34


NVD link : CVE-2020-5374

Mitre link : CVE-2020-5374

CVE.ORG link : CVE-2020-5374


JSON object : View

Products Affected

dell

  • emc_omimssc_for_sccm
  • emc_omimssc_for_scvmm
CWE
CWE-256

Plaintext Storage of a Password

CWE-798

Use of Hard-coded Credentials