Vulnerability record · CVE-2020-5377 · published 28 July 2020
CVE-2020-5377: Dell EMC OpenManage Server Administrator path traversal allows unauthenticated file access
Dell · Emc Openmanage Server Administrator
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities in its Web API. An unauthenticated remote attacker can send crafted requests with directory traversal sequences to reach files on the management station. Because OMSA is a management-plane component, compromise exposes the host it runs on.
Description
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit these vulnerabilities by sending a crafted Web API request containing directory traversal character sequences to gain file system access on the compromised management station.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with no authentication or user interaction required, high EPSS, and public exploit references make this a high-urgency management-plane flaw.
What it is
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities in its Web API. An unauthenticated remote attacker can send crafted requests with directory traversal sequences to reach files on the management station. Because OMSA is a management-plane component, compromise exposes the host it runs on.
Impact
An attacker gains file system access on the compromised management station, with the CVSS vector indicating high confidentiality and integrity impact but no availability impact. This can expose sensitive configuration and credential material on a management host.
Attack surface
Reached over the network via the OMSA Web API; the CVSS vector shows no privileges required and no user interaction, so the flaw is exploitable pre-authentication. Any reachable OMSA web interface is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.48 (98.8th percentile) and public exploit references exist, including a Packet Storm file-read writeup. No ransomware use is documented.
What to do
- Upgrade OMSA to a version later than 9.4 per Dell advisory DSA-2020-172; patch first.
- Restrict network access to the OMSA web interface to trusted management networks only.
- Do not expose OMSA directly to the internet or untrusted segments.
- Where OMSA is not needed, disable or remove it to reduce management-plane exposure.
- Monitor and rotate any credentials or secrets stored on hosts running vulnerable OMSA.
Detection
- Inspect OMSA web server and proxy logs for requests containing traversal sequences such as ../ or encoded variants.
- Alert on unusual file-read patterns or unexpected paths requested against the OMSA Web API.
- Baseline normal OMSA API callers and flag new or anomalous source IPs hitting the interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162110/Dell-OpenManage-Server-Administrator-9.4.0.0-File-Read.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.dell.com/support/article/en-us/sln322304/dsa-2020-172-dell-emc-openmanage-server-administrator-omsa-path-tra | Vendor Advisory |
| http://packetstormsecurity.com/files/162110/Dell-OpenManage-Server-Administrator-9.4.0.0-File-Read.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.dell.com/support/article/en-us/sln322304/dsa-2020-172-dell-emc-openmanage-server-administrator-omsa-path-tra | Vendor Advisory |
Track CVE-2020-5377 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.