CVE-2020-5357
Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.
Published:May 28, 2020
Last Modified:Nov 21, 2024
EPS:May 28, 2020
EPSS Score:0.0005
CVSS Score:7.1
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Dock Wd15
Dell
Dock Wd15
Vendor
Dell
Product
Dock Wd15 Firmware
Dell
Dock Wd15 Firmware
Vendor
Dell
Product
Dock Wd19
Dell
Dock Wd19
Vendor
Dell
Product
Dock Wd19 Firmware
Dell
Dock Wd19 Firmware
Vendor
Dell
Product
Precision Dual Usb-c Thunderbolt Dock - Tb18dc
Dell
Precision Dual Usb-c Thunderbolt Dock - Tb18dc
Vendor
Dell
Product
Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware
Dell
Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware
Vendor
Dell
Product
Thunderbolt Dock Tb16
Dell
Thunderbolt Dock Tb16
Vendor
Dell
Product
Thunderbolt Dock Tb16 Firmware
Dell
Thunderbolt Dock Tb16 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
