← Back

CVE-2020-5357

nvd nist
Published: May 28, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
Exploitability: 0.8 / Impact: 5.2
Source: NVD

Description

Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

Affected (4)

4 products
Dock Wd15 Firmware
Dock Wd19 Firmware
Thunderbolt Dock Tb16 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.8
Running on/withPlatform Versions
Dell
Dock Wd15
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.14
Running on/withPlatform Versions
Dell
Dock Wd19
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.4
Running on/withPlatform Versions
Dell
Thunderbolt Dock Tb16
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.0.10
Running on/withPlatform Versions
Dell
Precision Dual Usb C Thunderbolt Dock Tb18dc
All versions

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.