CVE-2020-5366
HIGHDell EMC iDRAC9 < 4.20.20.20 - Authenticated Path Traversal
Title source: llmDescription
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.dell.com/support/article/en-us/sln322125/dsa-2020-128-idrac-local-file-inclusion-vulnerability?lang=en
Scores
CVSS v3
7.1
EPSS
0.0043
EPSS Percentile
62.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Details
CWE
CWE-22
Status
published
Products (1)
dell/idrac9_firmware
< 4.20.20.20
Published
Jul 09, 2020
Tracked Since
Feb 18, 2026