PT-2018-2556 · Dell Emc · Dell Emc Avamar Client Manager+2

Jarrod Farncomb

·

Publicado

2018-11-20

·

Atualizado

2019-01-02

·

CVE-2018-11067

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC Avamar Server versions 7.2.0 through 7.5.1, 18.1 Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0 through 2.2
Description The issue is related to an open redirection vulnerability in the Dell EMC Avamar Client Manager component. A remote unauthenticated attacker could exploit this to redirect application users to arbitrary web URLs by tricking victims into clicking on maliciously crafted links. This could be used to conduct phishing attacks, causing users to unknowingly visit malicious sites.
Recommendations For Dell EMC Avamar Server versions 7.2.0 through 7.5.1 and 18.1, update to a version that includes a fix for the open redirection vulnerability. For Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0 through 2.2, update to a version that includes a fix for the open redirection vulnerability. As a temporary workaround, consider restricting access to the Avamar Client Manager component to minimize the risk of exploitation.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00975
CVE-2018-11067

Produtos afetados

Dell Emc Avamar Client Manager
Dell Emc Avamar Server
Dell Emc Integrated Data Protection Appliance