DSA-2020-081: Dell EMC Data Protection Advisor OS Command Injection Vulnerability

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Summary:    
Dell EMC Data Protection Advisor contains remediation for a security vulnerability that may be exploited by malicious users to compromise the affected system.

Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system.

CVE-2020-5352
8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system.

CVE-2020-5352
8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Affected products:    
Dell EMC Data Protection Advisor 6.4, 6.5, and 18.1

Remediation:
The following Dell EMC Data Protection Advisor releases address this vulnerability:    

  • Dell EMC Data Protection Advisor 18.2

  • Dell EMC Data Protection Advisor 19.1

  • Dell EMC Data Protection Advisor 19.2

Dell EMC recommends all customers upgrade at the earliest opportunity.



Affected products:    
Dell EMC Data Protection Advisor 6.4, 6.5, and 18.1

Remediation:
The following Dell EMC Data Protection Advisor releases address this vulnerability:    

  • Dell EMC Data Protection Advisor 18.2

  • Dell EMC Data Protection Advisor 19.1

  • Dell EMC Data Protection Advisor 19.2

Dell EMC recommends all customers upgrade at the earliest opportunity.



Acknowledgements

Dell EMC would like to thank Cyku from DEVCORE (https://devco.re) for reporting this vulnerability.

Related Information

Affected Products

Data Protection Advisor

Products

Data Protection Advisor, Product Security Information
Article Properties
Article Number: 000153706
Article Type: Dell Security Advisory
Last Modified: 19 Sep 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.