VYPR
Unrated severityNVD Advisory· Published Jul 9, 2020· Updated Sep 16, 2024

CVE-2020-5366

CVE-2020-5366

Description

Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path traversal vulnerability in Dell EMC iDRAC9 allows low-privileged authenticated users to read arbitrary files on the system.

Vulnerability

Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a path traversal vulnerability (CWE-22) in the handling of input parameters. A remote authenticated user with low privileges can manipulate these parameters to traverse outside the intended directory and access arbitrary files on the iDRAC filesystem [1].

Exploitation

An attacker must have network access to the iDRAC management interface and valid low-privilege credentials. No user interaction is required (CVSS:3.1/UI:N). By sending crafted HTTP requests with path traversal sequences (e.g., ../) in specific input parameters, the attacker can read files outside the restricted path [1].

Impact

Successful exploitation results in unauthorized read access to arbitrary files on the iDRAC. This can lead to disclosure of sensitive information such as configuration files, credentials, or other data stored on the device. The CVSS v3.1 base score is 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L), indicating high confidentiality impact, no integrity impact, and low availability impact [1].

Mitigation

Dell EMC has released iDRAC9 firmware version 4.20.20.20 which resolves this vulnerability. All users are advised to upgrade to this version or later at the earliest opportunity. As a best practice, iDRAC should be deployed on a separate management network and not exposed directly to the internet [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.