HIGH · 7.1

CVE-2020-5357

Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware U...

Vulnerability Description

Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellDock Wd15 Firmware< 1.0.8
DellDock Wd15-
DellDock Wd19 Firmware< 1.0.14
DellDock Wd19-
DellThunderbolt Dock Tb16 Firmware< 1.0.4
DellThunderbolt Dock Tb16-
DellPrecision Dual Usb-C Thunderbolt Dock - Tb18Dc Firmware< 1.0.10
DellPrecision Dual Usb-C Thunderbolt Dock - Tb18Dc-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-5357?

CVE-2020-5357 is a vulnerability with a CVSS score of 7.1 (HIGH). Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware U...

How severe is CVE-2020-5357?

CVE-2020-5357 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-5357?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Dock Wd15 Firmware, Dell Dock Wd15, Dell Dock Wd19 Firmware, Dell Dock Wd19, Dell Thunderbolt Dock Tb16 Firmware.