CVE-2020-5351Use of Hard-coded Password in Dell Data Protection Advisor

Severity
7.5HIGHNVD
EPSS
0.3%
top 47.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 28
Latest updateMay 24

Description

Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with limited privileges that is protected with a hard-coded password. A remote unauthenticated malicious user with the knowledge of the hard-coded password may login to the system and gain read-only privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5dell/data_protection_advisorunspecified6.4, 6.5, 18.1
NVDdell/emc_data_protection_advisor18.1, 6.4, 6.5+2

🔴Vulnerability Details

2
GHSA
GHSA-x6c3-g3xg-w487: Dell EMC Data Protection Advisor versions 62022-05-24
CVEList
CVE-2020-5351: Dell EMC Data Protection Advisor versions 62021-07-28
CVE-2020-5351 — Use of Hard-coded Password in Dell | cvebase