Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5385

Опубликовано: 18 авг. 2020
Источник: nvd
CVSS3: 6.7
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dell:encryption:*:*:*:*:enterprise:*:*:*
Версия до 10.8 (исключая)
cpe:2.3:a:dell:endpoint_security_suite_enterprise:*:*:*:*:*:*:*:*
Версия до 2.8 (исключая)

EPSS

Процентиль: 4%
0.00019
Низкий

6.7 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732
CWE-732

Связанные уязвимости

github
больше 3 лет назад

Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.

EPSS

Процентиль: 4%
0.00019
Низкий

6.7 Medium

CVSS3

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732
CWE-732