CVE-2020-5357
Summary
| CVE | CVE-2020-5357 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-28 20:15:00 UTC |
| Updated | 2020-05-29 20:02:00 UTC |
| Description | Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Dell | Dock Wd15 | - | All | All | All |
| Hardware | Dell | Dock Wd15 | - | All | All | All |
| Operating System | Dell | Dock Wd15 Firmware | All | All | All | All |
| Operating System | Dell | Dock Wd15 Firmware | All | All | All | All |
| Hardware | Dell | Dock Wd19 | - | All | All | All |
| Hardware | Dell | Dock Wd19 | - | All | All | All |
| Operating System | Dell | Dock Wd19 Firmware | All | All | All | All |
| Operating System | Dell | Dock Wd19 Firmware | All | All | All | All |
| Hardware | Dell | Precision Dual Usb-c Thunderbolt Dock - Tb18dc | - | All | All | All |
| Hardware | Dell | Precision Dual Usb-c Thunderbolt Dock - Tb18dc | - | All | All | All |
| Operating System | Dell | Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware | All | All | All | All |
| Operating System | Dell | Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware | All | All | All | All |
| Hardware | Dell | Thunderbolt Dock Tb16 | - | All | All | All |
| Hardware | Dell | Thunderbolt Dock Tb16 | - | All | All | All |
| Operating System | Dell | Thunderbolt Dock Tb16 Firmware | All | All | All | All |
| Operating System | Dell | Thunderbolt Dock Tb16 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2020-108: Dell Dock Firmware Update Utilities Arbitrary File Overwrite Vulnerability | Dell US | MISC | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.