Directory Traversal Vulnerability
CVE-2019-3720

4.9MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
25 April 2019

Summary

Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A remote authenticated malicious user with admin privileges could potentially exploit this vulnerability to gain unauthorized access to the file system by exploiting insufficient sanitization of input parameters.

Affected Version(s)

Open Manage System Administrator 9.3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell EMC would like to thank Harrison Neal for reporting this issue.
.