Security Advisory

CVE-2020-5350

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-04-15 18:00:18
Last updated 2024-09-16 17:54:54
Assigner dell
State PUBLISHED

Description

Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.