PT-2018-2556 · Dell Emc · Dell Emc Avamar Client Manager+2
Jarrod Farncomb
·
Published
2018-11-20
·
Updated
2019-01-02
·
CVE-2018-11067
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dell EMC Avamar Server versions 7.2.0 through 7.5.1, 18.1
Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0 through 2.2
Description
The issue is related to an open redirection vulnerability in the Dell EMC Avamar Client Manager component. A remote unauthenticated attacker could exploit this to redirect application users to arbitrary web URLs by tricking victims into clicking on maliciously crafted links. This could be used to conduct phishing attacks, causing users to unknowingly visit malicious sites.
Recommendations
For Dell EMC Avamar Server versions 7.2.0 through 7.5.1 and 18.1, update to a version that includes a fix for the open redirection vulnerability.
For Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0 through 2.2, update to a version that includes a fix for the open redirection vulnerability.
As a temporary workaround, consider restricting access to the Avamar Client Manager component to minimize the risk of exploitation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Avamar Client Manager
Dell Emc Avamar Server
Dell Emc Integrated Data Protection Appliance