Vulnerabilities > CVE-2020-5356 - Files or Directories Accessible to External Parties vulnerability in Dell products

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
dell
CWE-552

Summary

Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.

Vulnerable Configurations

Part Description Count
Application
Dell
1
OS
Dell
1
Hardware
Dell
1