PT-2021-12400 · Dell Emc · Dell Openmanage Enterprise

Published

2021-07-22

·

Updated

2021-08-02

·

CVE-2020-5370

CVSS v3.1

7.9

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dell EMC OpenManage Enterprise (OME) versions prior to 3.4
Description The issue allows a remote authenticated malicious user with high privileges to potentially exploit an arbitrary file overwrite vulnerability. This can be achieved via directory traversal sequences using a crafted tar file to inject malicious RPMs, which may cause a denial of service or perform unauthorized actions.
Recommendations For versions prior to 3.4, update to version 3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the directory traversal sequences and crafted tar files to minimize the risk of exploitation. Additionally, monitor system logs for suspicious activity and unauthorized actions.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5370

Affected Products

Dell Openmanage Enterprise