CVE-2020-5366

HIGH

Dell EMC iDRAC9 < 4.20.20.20 - Authenticated Path Traversal

Title source: llm
STIX 2.1

Description

Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

Scores

CVSS v3 7.1
EPSS 0.0043
EPSS Percentile 62.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Details

CWE
CWE-22
Status published
Products (1)
dell/idrac9_firmware < 4.20.20.20
Published Jul 09, 2020
Tracked Since Feb 18, 2026