CVE-2020-5386

HIGH

Dell EMC Elastic Cloud Storage < 3.5.0.0 - Unauthenticated Sensitive Data Exposure via Directory Table Objects

Title source: llm
STIX 2.1

Description

Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.

Scores

CVSS v3 7.5
EPSS 0.0088
EPSS Percentile 75.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-668
Status published
Products (1)
dell/emc_elastic_cloud_storage < 3.5.0.0
Published Sep 02, 2020
Tracked Since Feb 18, 2026