DSA-2020-080: Dell EMC Data Protection Advisor Hard-Coded Credential Vulnerability

Bu makale şunlar için geçerlidir: Bu makale şunlar için geçerli değildir: Bu makale, belirli bir ürüne bağlı değildir. Bu makalede tüm ürün sürümleri tanımlanmamıştır.

Impact

High

Details

Summary:    
Dell EMC Data Protection Advisor contains remediation for a hard-coded credential vulnerability that may be exploited by malicious users to compromise the affected system.

Hard-Coded Credential Vulnerability

Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 contain a hard-coded credential vulnerability in an undocumented account with limited privileges. A remote unauthenticated malicious user with the knowledge of the hard-coded password, may log in to the system and gain read-only privileges.

  • CVE-2020-5351

7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Hard-Coded Credential Vulnerability

Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1 contain a hard-coded credential vulnerability in an undocumented account with limited privileges. A remote unauthenticated malicious user with the knowledge of the hard-coded password, may log in to the system and gain read-only privileges.

  • CVE-2020-5351

7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Etkilenen Ürünler ve Düzeltme

Affected products:    
Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1

Remediation:
The following Dell EMC Data Protection Advisor releases address this vulnerability:    

  • Dell EMC Data Protection Advisor 18.2

  • Dell EMC Data Protection Advisor 19.1

  • Dell EMC Data Protection Advisor 19.2

Dell EMC recommends all customers upgrade at the earliest opportunity.



Affected products:    
Dell EMC Data Protection Advisor versions 6.4, 6.5, and 18.1

Remediation:
The following Dell EMC Data Protection Advisor releases address this vulnerability:    

  • Dell EMC Data Protection Advisor 18.2

  • Dell EMC Data Protection Advisor 19.1

  • Dell EMC Data Protection Advisor 19.2

Dell EMC recommends all customers upgrade at the earliest opportunity.



Acknowledgements

Dell EMC would like to thank Cyku from DEVCORE (https://devco.re) for reporting this vulnerability.

Related Information

Etkilenen Ürünler

Data Protection Advisor

Ürünler

Data Protection Advisor, Product Security Information
Makale Özellikleri
Article Number: 000153683
Article Type: Dell Security Advisory
Son Değiştirme: 19 Eyl 2025
Sorularınıza diğer Dell kullanıcılarından yanıtlar bulun
Destek Hizmetleri
Aygıtınızın Destek Hizmetleri kapsamında olup olmadığını kontrol edin.