Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.
References
Link | Resource |
---|---|
https://www.dell.com/support/article/en-us/sln322125/dsa-2020-128-idrac-local-file-inclusion-vulnerability?lang=en | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-07-09 07:15
Updated : 2020-07-15 11:18
NVD link : CVE-2020-5366
Mitre link : CVE-2020-5366
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
dell
- idrac9
- idrac9_firmware