← All CVEs

CVE-2020-5330

high · 8.1

Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could exploit this vulnerability to retrieve sensitive data by sending a specially crafted request to the affected endpoints.

8.1
CVSS
13.3%
EPSS (exploit prob.)
96th
EPSS percentile
2020-04-10
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
dellr1-2210_firmware<= 3.0.1.2
dellr1-2210all versions
dellr1-2401_firmware<= 3.0.1.2
dellr1-2401all versions
dellpc5500_firmware<= 4.1.0.22
dellpc5500all versions
dellx1000_firmware<= 2.0.0.77
dellx1000all versions
dellx4012_firmware<= 2.0.0.77
dellx4012all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-5330