SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-26182

Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability.

MEDIUM 6.5EPSS 0.72%

Does this matter?

Lower severity and a low EPSS score (0.72%). Track it; it rarely justifies an emergency change on its own.

Description

Dell EMC NetWorker versions prior to 19.3.0.2 contain an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.72% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-266, CWE-552
Affected
dell/emc networker
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.