CVE-2020-5330 EXPLOIT
8.1
HIGH · CVSS 3.1 · EPSS 13.3% (pctl 96)
Patch early
A public exploit exists.
Description
Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22 and older and Dell EMC PowerEdge VRTX Switch Modules firmware versions 2.0.0.77 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could exploit this vulnerability to retrieve sensitive data by sending a specially crafted request to the affected endpoints.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 13.26% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-04-10 |
| Last modified | 2026-06-17 |
Affected (10)
| Vendor | Product |
|---|---|
| dell | pc5500 |
| dell | pc5500 firmware |
| dell | r1-2210 |
| dell | r1-2210 firmware |
| dell | r1-2401 |
| dell | r1-2401 firmware |
| dell | x1000 |
| dell | x1000 firmware |
| dell | x4012 |
| dell | x4012 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure | 2023-04-05 |
References
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://www.dell.com/support/article/en-us/sln320366/dsa-2020-042-dell-emc-networking-security-update-for-an-information-disclosure-vulnerability?lang=en
- http://packetstormsecurity.com/files/171723/Cisco-Dell-Netgear-Information-Disclosure-Hash-Decrypter.html
- https://www.dell.com/support/article/en-us/sln320366/dsa-2020-042-dell-emc-networking-security-update-for-an-information-disclosure-vulnerability?lang=en
→ the Explorer · watch your stack · NVD