PT-2020-18440 · Dell Emc · Dell Openmanage Server Administrator

·

CVE-2020-5377

·

Published

2020-07-28

·

Updated

2023-12-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior
Description The issue allows an unauthenticated remote attacker to potentially exploit multiple path traversal vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.
Recommendations For versions 9.4 and prior, update to a version later than 9.4 to resolve the issue. As a temporary workaround, consider restricting access to the Web API to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5377

Affected Products

Dell Openmanage Server Administrator