DSA-2020-229: Dell EMC NetWorker Multiple Security Vulnerabilities
Impact
Medium
Details
Dell EMC NetWorker contains remediation for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
-
CVE-2020-26182
Dell EMC NetWorker contains an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP.
6.8 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N)
-
CVE-2020-26183
Dell EMC NetWorker contains an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner.
6.8 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N)
-
CVE-2020-26182
Dell EMC NetWorker contains an incorrect privilege assignment vulnerability. A non-LDAP remote user with low privileges may exploit this vulnerability to perform 'saveset' related operations in an unintended manner. The vulnerability is not exploitable by users authenticated via LDAP.
6.8 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N)
-
CVE-2020-26183
Dell EMC NetWorker contains an improper authorization vulnerability. Certain remote users with low privileges may exploit this vulnerability to perform 'nsrmmdbd' operations in an unintended manner.
6.8 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N)
Affected Products & Remediation
Affected products:
Dell EMC NetWorker version 19.3.0.1 and earlier
Dell EMC NetWorker version 19.2.1.2 and earlier
Remediation:
The following Dell EMC NetWorker releases address these vulnerabilities:
-
NetWorker version 19.3.0.2 or later
- NetWorker version 19.2.1.3 or later
Dell recommends all customers upgrade at the earliest opportunity.
Affected products:
Dell EMC NetWorker version 19.3.0.1 and earlier
Dell EMC NetWorker version 19.2.1.2 and earlier
Remediation:
The following Dell EMC NetWorker releases address these vulnerabilities:
-
NetWorker version 19.3.0.2 or later
- NetWorker version 19.2.1.3 or later
Dell recommends all customers upgrade at the earliest opportunity.