Path traversal in iDRAC9 - CVE-2020-5366
Published: August 20, 2020
Vulnerability identifier: #VU45801
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5366
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated user can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
iDRAC9
PowerFlex rack
EMC ECS
Dell EMC VxRail Appliance
EMC Data Domain
PowerFlex rack
EMC ECS
Dell EMC VxRail Appliance
EMC Data Domain
How to mitigate CVE-2020-5366
Install update from vendor's website.
iDRAC9 - update to 4.20.20.20
PowerFlex rack - addressed in versions 3.3.8.1, 3.4.3.1, 3.5.3.1
EMC ECS - addressed in versions 3.5.1.1, 3.6
Dell EMC VxRail Appliance - update to 4.5.450
EMC Data Domain - addressed in versions 6.2.1.40, 7.1.0.30, 7.2.0.20, 7.2.0.50, 7.4
PowerFlex rack - addressed in versions 3.3.8.1, 3.4.3.1, 3.5.3.1
EMC ECS - addressed in versions 3.5.1.1, 3.6
Dell EMC VxRail Appliance - update to 4.5.450
EMC Data Domain - addressed in versions 6.2.1.40, 7.1.0.30, 7.2.0.20, 7.2.0.50, 7.4