Vulnerability Description
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Encryption | < 10.8 |
| Dell | Endpoint Security Suite Enterprise | < 2.8 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/article/SLN322456Vendor Advisory
- https://www.dell.com/support/article/SLN322456Vendor Advisory
FAQ
What is CVE-2020-5385?
CVE-2020-5385 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malic...
How severe is CVE-2020-5385?
CVE-2020-5385 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5385?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Encryption, Dell Endpoint Security Suite Enterprise.