« Volver al listado

CVE-2020-5368

Estado: ModificadaAlta (7.5)—

Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5368",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "VxRail",
          "versions": [
            {
              "status": "affected",
              "version": "4.7.410, 4.7.411"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-07-06T18:15:20.950",
  "references": [
    {
      "url": "https://www.dell.com/support/security/en-us/details/544058/DSA-2020-136-Dell-EMC-VxRail-Appliance-Improper-Authentication-Vulnerability",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/security/en-us/details/544058/DSA-2020-136-Dell-EMC-VxRail-Appliance-Improper-Authentication-Vulnerability",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form."
    },
    {
      "lang": "es",
      "value": "Dell EMC VxRail versiones 4.7.410 y 4.7.411, contiene una vulnerabilidad de autenticación inapropiada. Un atacante no autenticado remoto puede explotar esta vulnerabilidad para obtener información confidencial en forma cifrada"
    }
  ],
  "lastModified": "2026-06-17T03:21:21.973",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:vxrail_d560f_firmware:4.7.410:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DECEDCF-1EC6-4497-A17E-C35F881808E0"
            },
            {
              "criteria": "cpe:2.3:o:dell:vxrail_d560f_firmware:4.7.411:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "216552D1-8E9F-4712-8F81-0E7F6B59BC9C"
            },
            {
              "criteria": "cpe:2.3:o:dell:vxrail_d560f_firmware:4.7.510:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81918932-436C-4D65-A1F2-A411E1872C41"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:vxrail_d560f:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7755F292-5841-4751-AA28-2766B510F4B1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:vxrail_d560_firmware:4.7.410:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8935BBAA-068E-4537-8BA7-38FB952DB436"
            },
            {
              "criteria": "cpe:2.3:o:dell:vxrail_d560_firmware:4.7.411:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35BEE2D5-32C6-4F58-B422-444038416A6F"
            },
            {
              "criteria": "cpe:2.3:o:dell:vxrail_d560_firmware:4.7.510:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9865DF11-664C-4664-9C0E-ABA051436F43"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:vxrail_d560:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0B547BDB-12A9-40AC-B4CA-040F413C5F05"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}