CVE-2020-5372
06.07.2020, 18:15
Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test interface ports which are not used during run time environment.Enginsight
Vendor | Product | Version |
---|---|---|
dell | emc_powerstore_1000_firmware | 𝑥 < 1.0.1.0.5.002 |
dell | emc_powerstore_3000_firmware | 𝑥 < 1.0.1.0.5.002 |
dell | emc_powerstore_5000_firmware | 𝑥 < 1.0.1.0.5.002 |
dell | emc_powerstore_7000_firmware | 𝑥 < 1.0.1.0.5.002 |
dell | emc_powerstore_9000_firmware | 𝑥 < 1.0.1.0.5.002 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1244 - Internal Asset Exposed to Unsafe Debug Access Level or StateThe product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.