HIGH · 7.5

CVE-2020-5319

Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service...

Vulnerability Description

Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of Service (Storage Processor Panic) by sending an out of order SSH protocol sequence.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
DellEmc Unity Operating Environment< 5.0.2.0.5.009
DellEmc Unity Xt Operating Environment< 5.0.2.0.5.009
DellEmc Unityvsa Operating Environment< 5.0.2.0.5.009

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5319?

CVE-2020-5319 is a vulnerability with a CVSS score of 7.5 (HIGH). Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service...

How severe is CVE-2020-5319?

CVE-2020-5319 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5319?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Unity Operating Environment, Dell Emc Unity Xt Operating Environment, Dell Emc Unityvsa Operating Environment.