DSA-2020-079: Dell EMC Integrated Data Protection Appliance Command Injection Vulnerability
Impact
High
Détails
Summary:
Dell EMC Integrated Data Protection Appliance contains remediation for a Command Injection Vulnerability that may be exploited by malicious users to compromise the affected system.
Command Injection Vulnerability
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, and 2.4 contain a command injection vulnerability in the Appliance Configuration Manager component. A remote authenticated malicious user with root privileges may inject parameters in the Appliance Configuration Manager component APIs that may lead to manipulation of passwords and execution of malicious commands on Appliance Configuration Manager component.
CVE-2020-5350
7.9 (AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H)
Command Injection Vulnerability
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, and 2.4 contain a command injection vulnerability in the Appliance Configuration Manager component. A remote authenticated malicious user with root privileges may inject parameters in the Appliance Configuration Manager component APIs that may lead to manipulation of passwords and execution of malicious commands on Appliance Configuration Manager component.
CVE-2020-5350
7.9 (AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H)
Produits concernés et mesure corrective
Affected products:
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4
Remediation:
The following Dell EMC Integrated Data Protection Appliance release addresses this vulnerability:
-
Dell EMC Integrated Data Protection Appliance 2.5
https://download.emc.com/downloads/DL97800_IDPA-2.5-Upgrade.tar.gz
Note: Integrated Data Protection Appliance 2.0 customers will have to upgrade to 2.1 first, then to 2.3.1 and then to 2.5 in order to remediate from these vulnerabilities.
Dell EMC recommends all customers upgrade at the earliest opportunity.
Affected products:
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4
Remediation:
The following Dell EMC Integrated Data Protection Appliance release addresses this vulnerability:
-
Dell EMC Integrated Data Protection Appliance 2.5
https://download.emc.com/downloads/DL97800_IDPA-2.5-Upgrade.tar.gz
Note: Integrated Data Protection Appliance 2.0 customers will have to upgrade to 2.1 first, then to 2.3.1 and then to 2.5 in order to remediate from these vulnerabilities.
Dell EMC recommends all customers upgrade at the earliest opportunity.