8.6

CVE-2020-5372

Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.

Data is provided by the National Vulnerability Database (NVD)
DellEmc Powerstore 1000 Firmware Version < 1.0.1.0.5.002
   DellEmc Powerstore 1000 Version-
DellEmc Powerstore 3000 Firmware Version < 1.0.1.0.5.002
   DellEmc Powerstore 3000 Version-
DellEmc Powerstore 5000 Firmware Version < 1.0.1.0.5.002
   DellEmc Powerstore 5000 Version-
DellEmc Powerstore 7000 Firmware Version < 1.0.1.0.5.002
   DellEmc Powerstore 7000 Version-
DellEmc Powerstore 9000 Firmware Version < 1.0.1.0.5.002
   DellEmc Powerstore 9000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.66% 0.687
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
security_alert@emc.com 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CWE-1244 Internal Asset Exposed to Unsafe Debug Access Level or State

The product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.