PT-2018-2865 · Dell Emc · Dell Emc Integrated Data Protection Appliance+1
Publicado
2018-11-20
·
Atualizado
2020-08-24
·
CVE-2018-11076
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dell EMC Avamar Server versions 7.2.0 through 7.4.1
Dell EMC Integrated Data Protection Appliance (IDPA) version 2.0
Description
The issue is related to an information exposure vulnerability. The Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. This could potentially be used by an unauthenticated attacker on the same data-link layer to initiate a MITM attack on management console users. Additionally, the vulnerability may allow a remote attacker to execute arbitrary commands with root privileges due to the lack of neutralization of special elements used in the operating system command.
Recommendations
For Dell EMC Avamar Server versions 7.2.0 through 7.4.1, consider disabling the Avamar Java management console until a patch is available to prevent potential MITM attacks.
For Dell EMC Integrated Data Protection Appliance (IDPA) version 2.0, restrict access to the management console to minimize the risk of exploitation.
As a temporary workaround, avoid using the Avamar Java management client package until the issue is resolved.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Emc Avamar Server
Dell Emc Integrated Data Protection Appliance