SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5377

Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.

CRITICAL 9.1EPSS 48.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 48.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
48.33% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
dell/emc openmanage server administrator
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.