Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5327

Опубликовано: 06 мар. 2020
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
CVSS2: 9.3
EPSS Низкий

Описание

Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:security_management_server:*:*:*:*:*:*:*:*
Версия до 10.2.10 (исключая)

EPSS

Процентиль: 89%
0.05044
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-502
CWE-502

Связанные уязвимости

github
больше 3 лет назад

Dell Security Management Server versions prior to 10.2.10 contain a Java RMI Deserialization of Untrusted Data vulnerability. When the server is exposed to the internet and Windows Firewall is disabled, a remote unauthenticated attacker may exploit this vulnerability by sending a crafted RMI request to execute arbitrary code on the target host.

EPSS

Процентиль: 89%
0.05044
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-502
CWE-502