Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to manipulation of passwords and execution of malicious commands on ACM component.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2020-04-15T18:00:18.727517Z
Updated: 2024-09-16T17:54:54.783Z
Reserved: 2020-01-03T00:00:00
Link: CVE-2020-5350
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-15T18:15:15.693
Modified: 2024-11-21T05:33:57.823
Link: CVE-2020-5350
Redhat
No data.