CVE-2020-5386

HIGH

Dell Emc Elastic Cloud Storage < 3.5.0.0 - Exposure to Wrong Actor

Title source: rule

Description

Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.

Scores

CVSS v3 7.5
EPSS 0.0088
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (1)

dell/emc_elastic_cloud_storage < 3.5.0.0

Timeline

Published Sep 02, 2020
Tracked Since Feb 18, 2026