CVE-2020-5377
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 48.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 48.33% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- dell/emc openmanage server administrator
- Source
- security_alert@emc.com
References
- http://packetstormsecurity.com/files/162110/Dell-OpenManage-Server-Administrator-9.4.0.0-File-Read.htmlExploit, Third Party Advisory, VDB Entry
- https://www.dell.com/support/article/en-us/sln322304/dsa-2020-172-dell-emc-openmanage-server-administrator-omsa-path-traversal-vulnerability?lang=enVendor Advisory
- http://packetstormsecurity.com/files/162110/Dell-OpenManage-Server-Administrator-9.4.0.0-File-Read.htmlExploit, Third Party Advisory, VDB Entry
- https://www.dell.com/support/article/en-us/sln322304/dsa-2020-172-dell-emc-openmanage-server-administrator-omsa-path-traversal-vulnerability?lang=enVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.