CVE-2020-5367 HIGH

CVE-2020-5367

Vendor Dell
Product Unisphere for PowerMax, Unisphere for PowerMax Virtual Appliance, PowerMax OS
Weakness CWE-295
Published June 23, 2020
Last update September 16, 2024

CVSS base score

7.4/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim's data in transit.

Key dates

02Disclosure timeline

June 23, 2020 CVE published
September 16, 2024 Record updated