CVE-2020-5319

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/02/2020
Last modified:
12/02/2020

Description

Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of Service (Storage Processor Panic) by sending an out of order SSH protocol sequence.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:emc_unity_operating_environment:*:*:*:*:*:*:*:* 5.0.2.0.5.009 (excluding)
cpe:2.3:a:dell:emc_unity_xt_operating_environment:*:*:*:*:*:*:*:* 5.0.2.0.5.009 (excluding)
cpe:2.3:a:dell:emc_unityvsa_operating_environment:*:*:*:*:*:*:*:* 5.0.2.0.5.009 (excluding)