CVE-2020-5330
high · 8.1Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could exploit this vulnerability to retrieve sensitive data by sending a specially crafted request to the affected endpoints.
8.1
CVSS
13.3%
EPSS (exploit prob.)
96th
EPSS percentile
2020-04-10
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-200
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| dell | r1-2210_firmware | <= 3.0.1.2 |
| dell | r1-2210 | all versions |
| dell | r1-2401_firmware | <= 3.0.1.2 |
| dell | r1-2401 | all versions |
| dell | pc5500_firmware | <= 4.1.0.22 |
| dell | pc5500 | all versions |
| dell | x1000_firmware | <= 2.0.0.77 |
| dell | x1000 | all versions |
| dell | x4012_firmware | <= 2.0.0.77 |
| dell | x4012 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://www.dell.com/support/article/en-us/sln320366/dsa-2020-042-dell-emc-networking-security-update-for-an-information-disclosure-vulnerability?lang=en
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://www.dell.com/support/article/en-us/sln320366/dsa-2020-042-dell-emc-networking-security-update-for-an-information-disclosure-vulnerability?lang=en
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-5330