CVE-2020-5343

HIGH

Dell OS Recovery Image For Microsoft ... - Incorrect Authorization

Title source: rule
STIX 2.1

Description

Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vulnerability to gain unauthorized access on the root folder.

Scores

CVSS v3 7.3
EPSS 0.0002
EPSS Percentile 5.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-277 CWE-863
Status published
Products (1)
dell/os_recovery_image_for_microsoft_windows_10 < 2019-12-20
Published May 04, 2020
Tracked Since Feb 18, 2026