vendor:
Networking PC5500 firmware
by:
Ken 's1ngular1ty' Pyle
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Networking PC5500 firmware
Affected Version From: 4.1.0.22
Affected Version To: 4.1.0.22
Patch Exists: YES
Related CWE: CVE-2019-15993, CVE-2020-5330
CPE: o:dell:emc_networking_pc5500_firmware:4.1.0.22
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=119675, https://www.infosecmatter.com/nessus-plugin-library/?id=119676, https://www.infosecmatter.com/nessus-plugin-library/?id=119673, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/misc/vmhgfs_webdav_dll_sideload, https://www.infosecmatter.com/nessus-plugin-library/?id=92943, https://www.infosecmatter.com/nessus-plugin-library/?id=92944, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Platforms Tested: Cisco Sx / SMB
2020
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB – Information Disclosure
This vulnerability allows an attacker to gain access to sensitive information stored on a vulnerable system. It affects Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable system. Successful exploitation of this vulnerability can result in the disclosure of sensitive information.
Mitigation:
Users should update to the latest version of the affected software. Additionally, users should ensure that all passwords are strong and not easily guessed.