Learn about CVE-2020-5377, a critical vulnerability in Dell EMC OpenManage Server Administrator versions 9.4 and earlier. Understand the impact, affected systems, exploitation mechanism, and mitigation steps.
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities that could be exploited by remote attackers. This CVE was published on July 26, 2020.
Understanding CVE-2020-5377
This CVE pertains to path traversal vulnerabilities in Dell Open Manage Server Administrator.
What is CVE-2020-5377?
CVE-2020-5377 refers to multiple path traversal vulnerabilities in Dell EMC OpenManage Server Administrator versions 9.4 and earlier. Attackers could exploit these vulnerabilities remotely without authentication.
The Impact of CVE-2020-5377
The impact of this CVE is critical, with a CVSS base score of 9.1. It poses high confidentiality and integrity risks, allowing attackers to gain file system access on compromised management stations.
Technical Details of CVE-2020-5377
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The vulnerability involves improper handling of directory traversal character sequences in crafted Web API requests, enabling unauthorized access to the file system.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2020-5377 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates