DSA-2020-079: Dell EMC Integrated Data Protection Appliance Command Injection Vulnerability

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Impact

High

Détails

Summary:    
Dell EMC Integrated Data Protection Appliance contains remediation for a Command Injection Vulnerability that may be exploited by malicious users to compromise the affected system.

Command Injection Vulnerability

Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, and 2.4 contain a command injection vulnerability in the Appliance Configuration Manager component. A remote authenticated malicious user with root privileges may inject parameters in the Appliance Configuration Manager component APIs that may lead to manipulation of passwords and execution of malicious commands on Appliance Configuration Manager component.

CVE-2020-5350
7.9 (AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H)

Command Injection Vulnerability

Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, and 2.4 contain a command injection vulnerability in the Appliance Configuration Manager component. A remote authenticated malicious user with root privileges may inject parameters in the Appliance Configuration Manager component APIs that may lead to manipulation of passwords and execution of malicious commands on Appliance Configuration Manager component.

CVE-2020-5350
7.9 (AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H)

Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.

Produits concernés et mesure corrective

Affected products:    
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4

Remediation:
The following Dell EMC Integrated Data Protection Appliance release addresses this vulnerability:    

  • Dell EMC Integrated Data Protection Appliance 2.5

https://download.emc.com/downloads/DL97800_IDPA-2.5-Upgrade.tar.gz

Note: Integrated Data Protection Appliance 2.0 customers will have to upgrade to 2.1 first, then to 2.3.1 and then to 2.5 in order to remediate from these vulnerabilities.

Dell EMC recommends all customers upgrade at the earliest opportunity.



Affected products:    
Dell EMC Integrated Data Protection Appliance 2.0
Dell EMC Integrated Data Protection Appliance 2.1
Dell EMC Integrated Data Protection Appliance 2.2
Dell EMC Integrated Data Protection Appliance 2.3
Dell EMC Integrated Data Protection Appliance 2.4

Remediation:
The following Dell EMC Integrated Data Protection Appliance release addresses this vulnerability:    

  • Dell EMC Integrated Data Protection Appliance 2.5

https://download.emc.com/downloads/DL97800_IDPA-2.5-Upgrade.tar.gz

Note: Integrated Data Protection Appliance 2.0 customers will have to upgrade to 2.1 first, then to 2.3.1 and then to 2.5 in order to remediate from these vulnerabilities.

Dell EMC recommends all customers upgrade at the earliest opportunity.



Informations connexes

Produits concernés

PowerProtect Data Protection Software

Produits

PowerProtect DP4400, PowerProtect DP5300, PowerProtect DP5800, PowerProtect DP8300, PowerProtect DP8800, PowerProtect Data Protection Software, Integrated Data Protection Appliance Family, PowerProtect Data Protection Hardware , Integrated Data Protection Appliance Software, Product Security Information ...
Propriétés de l’article
Numéro d’article: 000153582
Type d’article: Dell Security Advisory
Dernière modification: 19 sept. 2025
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.