PT-2021-12400 · Dell Emc · Dell Openmanage Enterprise
Published
2021-07-22
·
Updated
2021-08-02
·
CVE-2020-5370
CVSS v3.1
7.9
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Dell EMC OpenManage Enterprise (OME) versions prior to 3.4
Description
The issue allows a remote authenticated malicious user with high privileges to potentially exploit an arbitrary file overwrite vulnerability. This can be achieved via directory traversal sequences using a crafted tar file to inject malicious RPMs, which may cause a denial of service or perform unauthorized actions.
Recommendations
For versions prior to 3.4, update to version 3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the directory traversal sequences and crafted tar files to minimize the risk of exploitation. Additionally, monitor system logs for suspicious activity and unauthorized actions.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Openmanage Enterprise