MEDIUM · 6.4

CVE-2020-5345

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass v...

Vulnerability Description

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass vulnerability. An authenticated malicious user may potentially execute commands to alter or stop database statistics.

CVSS Score

6.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
DellEmc Unisphere For Powermax< 9.1.0.17
DellEmc Unisphere For Powermax Virtual Appliance< 9.1.0.17
DellPowermax Os5978

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5345?

CVE-2020-5345 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an authorization bypass v...

How severe is CVE-2020-5345?

CVE-2020-5345 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5345?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Emc Unisphere For Powermax, Dell Emc Unisphere For Powermax Virtual Appliance, Dell Powermax Os.