8.6
CVE-2020-5372
- EPSS 0.66%
- Veröffentlicht 06.07.2020 18:15:21
- Zuletzt bearbeitet 21.11.2024 05:34:01
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Emc Powerstore 1000 Firmware Version < 1.0.1.0.5.002
Dell ≫ Emc Powerstore 3000 Firmware Version < 1.0.1.0.5.002
Dell ≫ Emc Powerstore 5000 Firmware Version < 1.0.1.0.5.002
Dell ≫ Emc Powerstore 7000 Firmware Version < 1.0.1.0.5.002
Dell ≫ Emc Powerstore 9000 Firmware Version < 1.0.1.0.5.002
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.66% | 0.687 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
security_alert@emc.com | 8.6 | 3.9 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
|
CWE-1244 Internal Asset Exposed to Unsafe Debug Access Level or State
The product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.