Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-5322

CVSS 9.1 · Critical EPSS 3.34% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-5322

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
DELL EMC OpenManage Enterprise-Modular 操作系统操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DELL EMC OpenManage Enterprise-Modular是美国戴尔(DELL)公司的一个应用程序。 Dell EMC OpenManage Enterprise-Modular(OME-M)1.10.00之前版本中存在操作系统命令注入漏洞。远程攻击者可利用该漏洞在受影响的系统上执行任意Shell命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
DellDell OpenManage Enterprise Modular unspecified ~ 1.10 -

II. Public POCs for CVE-2020-5322

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-5322

Please Login to view more intelligence information

Same Patch Batch · Dell · 2021-07-19 · 8 CVEs total

CVE-2020-53499.8 CRITICALDell EMC Networking S4100 和 S5200 信任管理问题漏洞
CVE-2020-53209.0 CRITICALDELL EMC OpenManage Enterprise和DELL EMC OpenManage Enterprise-Modular SQL注入漏洞
CVE-2020-53158.8 HIGHDELL EMC Repository Manager 安全漏洞
CVE-2020-53217.6 HIGHDell EMC OpenManage Enterprise和OpenManage Enterprise-Modular 输入验证错误漏洞
CVE-2020-294996.4 MEDIUMDell EMC PowerStore 操作系统命令注入漏洞
CVE-2020-53235.4 MEDIUMDELL EMC OpenManage Enterprise和DELL EMC OpenManage Enterprise-Modular 注入漏洞
CVE-2020-295034.1 MEDIUMDell EMC PowerStore 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-5322

No comments yet


Leave a comment