CVE-2020-5372
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.0.5.002 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Powerstore 1000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.0.5.002 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Powerstore 3000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.0.5.002 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Powerstore 5000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.0.5.002 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Powerstore 7000 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.0.5.002 |
| Running on/with | Platform Versions |
|---|---|
Dell Emc Powerstore 9000 | All versions |
Related CWEs
CWE-1244
Internal Asset Exposed to Unsafe Debug Access Level or State
The product uses physical debug or test
interfaces with support for multiple access levels, but it
assigns the wrong debug access level to an internal asset,
providing unintended access to the asset from untrusted debug
agents.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (2)
Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.