Dell Identifier: DSA-2020-042
CVE Identifier: CVE-2020-5330
Severity Rating: 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Dell X-Series firmware versions 220.127.116.11 and older
Dell PC5500 firmware versions 18.104.22.168 and older
Dell VRTX Switches firmware versions 22.214.171.124 and older
Dell X-Series, PC5500 series and VRTX Switch Modules require mitigation for a security vulnerability that could be exploited by malicious users to compromise the affected system. This security advisory has been updated to include the resolution for Dell X-Series, Dell PC5500 Series and VRTX Series Switches.
Information Disclosure Vulnerability
Dell X-Series firmware versions 126.96.36.199 and older, Dell PC5500 firmware versions 188.8.131.52 and older and VRTX Switch Modules firmware versions 184.108.40.206 and older contain an information disclosure vulnerability. A remote unauthenticated attacker could exploit this vulnerability to retrieve sensitive data by sending a specially crafted request to the affected endpoints.
The following Dell Networking release contains resolutions to these vulnerabilities:
VRTX Series Switches:
R1-2210 : http://www.dell.com/support/home/Drivers/DriversDetails?driverId=W4W2D
Dell PC5500 Series:
PC5500 Series: http://www.dell.com/support/home/Drivers/DriversDetails?driverId=VP09H
Dell Networking X-Series:
Dell recommends all customers upgrade at the earliest opportunity.
Dell would like to thank Ken Pyle for reporting this vulnerability.
For an explanation of Severity Ratings, refer to Dell Vulnerability Response Policy. Dell recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.
Read and use the information in this Dell Security Advisory to assist in avoiding any situation that might arise from the problems described herein. Dell distributes Dell Security Advisories, in order to bring to the attention of users of the affected Dell , important security information.
Dell recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided “as is” without warranty of any kind. Dell disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event, shall Dell or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.
Article ID: SLN320366
Last Date Modified: 05/05/2020 12:02 PM