CVE-2020-5366
Description
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a Path Traversal Vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in Dell EMC iDRAC9 allows low-privileged authenticated users to read arbitrary files on the system.
Vulnerability
Dell EMC iDRAC9 versions prior to 4.20.20.20 contain a path traversal vulnerability (CWE-22) in the handling of input parameters. A remote authenticated user with low privileges can manipulate these parameters to traverse outside the intended directory and access arbitrary files on the iDRAC filesystem [1].
Exploitation
An attacker must have network access to the iDRAC management interface and valid low-privilege credentials. No user interaction is required (CVSS:3.1/UI:N). By sending crafted HTTP requests with path traversal sequences (e.g., ../) in specific input parameters, the attacker can read files outside the restricted path [1].
Impact
Successful exploitation results in unauthorized read access to arbitrary files on the iDRAC. This can lead to disclosure of sensitive information such as configuration files, credentials, or other data stored on the device. The CVSS v3.1 base score is 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L), indicating high confidentiality impact, no integrity impact, and low availability impact [1].
Mitigation
Dell EMC has released iDRAC9 firmware version 4.20.20.20 which resolves this vulnerability. All users are advised to upgrade to this version or later at the earliest opportunity. As a best practice, iDRAC should be deployed on a separate management network and not exposed directly to the internet [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.