CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-29493

CVSS 10.0v3.1pub. 2021-01-14upd. 2024-11-21

DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Dell Emc Avamar Server

    APP
    Dell
    19.119.219.3
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    2.52.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2020-5341CRITICAL9.8PL ✓same product

RCE poprzez Deserialization w Dell EMC Avamar Server i IDPA

CVE-2020-29495CRITICAL10.0PL ✓same product

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2018-11066CRITICAL9.8PL ✓same product

RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia

CVE-2018-1217CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających

CVE-2021-21601HIGH8.8same product

Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in...