CVE-2020-5350
15.04.2020, 18:15
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
| Vendor | Product | Version |
|---|---|---|
| dell | emc_integrated_data_protection_appliance | 2.0 |
| dell | emc_integrated_data_protection_appliance | 2.1 |
| dell | emc_integrated_data_protection_appliance | 2.2 |
| dell | emc_integrated_data_protection_appliance | 2.3 |
| dell | emc_integrated_data_protection_appliance | 2.4 |
𝑥
= Vulnerable software versions
References