DSA-2020-081: Dell EMC Data Protection Advisor OS Command Injection Vulnerability
Impact
High
Details
Summary:
Dell EMC Data Protection Advisor contains remediation for a security vulnerability that may be exploited by malicious users to compromise the affected system.
Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system.
CVE-2020-5352
8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 contain an OS command injection vulnerability. A remote authenticated malicious user may exploit this vulnerability to execute arbitrary commands on the affected system.
CVE-2020-5352
8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Products & Remediation
Affected products:
Dell EMC Data Protection Advisor 6.4, 6.5, and 18.1
Remediation:
The following Dell EMC Data Protection Advisor releases address this vulnerability:
-
Dell EMC Data Protection Advisor 18.2
-
Dell EMC Data Protection Advisor 19.1
-
Dell EMC Data Protection Advisor 19.2
Dell EMC recommends all customers upgrade at the earliest opportunity.
Affected products:
Dell EMC Data Protection Advisor 6.4, 6.5, and 18.1
Remediation:
The following Dell EMC Data Protection Advisor releases address this vulnerability:
-
Dell EMC Data Protection Advisor 18.2
-
Dell EMC Data Protection Advisor 19.1
-
Dell EMC Data Protection Advisor 19.2
Dell EMC recommends all customers upgrade at the earliest opportunity.
Acknowledgements
Dell EMC would like to thank Cyku from DEVCORE (https://devco.re) for reporting this vulnerability.