MEDIUM🇵🇱 Wersja polska

CVE-2018-11076

CVSS 6.5v3.0pub. 2018-11-26upd. 2024-11-21

Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private key could potentially be used by an unauthenticated attacker on the same data-link layer to initiate a MITM attack on management console users.

CVSS Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Dell Emc Avamar

    APP
    Dell
    7.2.07.2.17.3.07.3.17.4.07.4.1
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    2.0
  • VMware vSphere Data Protection

    APP
    Vmware
    6.0.06.0.16.0.26.0.36.0.46.0.56.0.66.0.76.0.86.1.06.1.16.1.26.1.36.1.46.1.5+ 4 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-29493CRITICAL10.0PL ✓same product

SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych

CVE-2020-29495CRITICAL10.0PL ✓same product

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2018-11066CRITICAL9.8PL ✓same product

RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia

CVE-2018-1217CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających

CVE-2017-4914CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu przez błąd deserializacji w VMware vSphere Data Protection