CVE-2020-5356
Last modified
CVE-2020-5356 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Powerprotect Data Manager | < 19.4 |
| Dell | Powerprotect X400 Firmware | < 3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5356?
How severe is CVE-2020-5356?
How do I fix CVE-2020-5356?
Are you affected by CVE-2020-5356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
