Hopp til hovedinnhold
  • Legg inn bestillinger raskt og enkelt
  • Vis bestillinger og spor forsendelsesstatus
  • Opprett og få tilgang til en liste over produktene dine
  • Administrer Dell EMC-områder, produkter og kontakter for produktnivå ved hjelp av virksomhetsadministrering.

Artikkelnummer: 000153623


DSA-2020-099: Dell PowerProtect Data Manager Improper Authorization Vulnerability

Artikkelinnhold


Påvirkning

High

Detaljer

Summary:    
Dell PowerProtect Data Manager contains remediation for a security vulnerability that may be exploited by malicious users to compromise the affected system.

Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.

CVE-2020-5356
7.7(AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.  

To search for a CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search

Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.

CVE-2020-5356
7.7(AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm.  

To search for a CVE, use the database s search utility at http://web.nvd.nist.gov/view/vuln/search

Dell Technologies anbefaler at alle kunder tar hensyn til både grunnpoengsummen og alle relevante, midlertidige og miljømessige resultater som kan påvirke den potensielle alvorlighetsgraden knyttet til bestemte sikkerhetsproblemer.

Berørte produkter og utbedring

Affected products:       
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4
Dell PowerProtect X400 versions prior to 3.2


Remediation:    
The following Dell PowerProtect releases address this vulnerability:   

  • Dell PowerProtect Data Manager 19.4

  • Dell PowerProtect X400 version 3.2

Dell recommends all customers upgrade at the earliest opportunity. Contact Dell PowerProtect Data Manager Customer Support to download the required binary files and install it.



Affected products:       
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4
Dell PowerProtect X400 versions prior to 3.2


Remediation:    
The following Dell PowerProtect releases address this vulnerability:   

  • Dell PowerProtect Data Manager 19.4

  • Dell PowerProtect X400 version 3.2

Dell recommends all customers upgrade at the earliest opportunity. Contact Dell PowerProtect Data Manager Customer Support to download the required binary files and install it.



Relatert informasjon


Artikkelegenskaper


Berørt produkt

PowerProtect Data Manager

Produkt

PowerProtect Data Manager, PowerProtect X400 Appliance, Product Security Information

Dato for siste publisering

22 mai 2021

Versjon

4

Artikkeltype

Dell Security Advisory