CVE-2020-5319
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/02/2020
Last modified:
12/02/2020
Description
Dell EMC Unity, Dell EMC Unity XT, and Dell EMC UnityVSA versions prior to 5.0.2.0.5.009 contain a Denial of Service vulnerability on NAS Server SSH implementation that is used to provide SFTP service on a NAS server. A remote unauthenticated attacker may potentially exploit this vulnerability and cause a Denial of Service (Storage Processor Panic) by sending an out of order SSH protocol sequence.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dell:emc_unity_operating_environment:*:*:*:*:*:*:*:* | 5.0.2.0.5.009 (excluding) | |
| cpe:2.3:a:dell:emc_unity_xt_operating_environment:*:*:*:*:*:*:*:* | 5.0.2.0.5.009 (excluding) | |
| cpe:2.3:a:dell:emc_unityvsa_operating_environment:*:*:*:*:*:*:*:* | 5.0.2.0.5.009 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



