First published: Tue Jan 12 2021(Updated: )
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Avamar Server | =19.1 | |
Dell EMC Avamar Server | =19.2 | |
Dell EMC Avamar Server | =19.3 | |
Dell EMC Integrated Data Protection Appliance | =2.5 | |
Dell EMC Integrated Data Protection Appliance | =2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-29493 is critical with a CVSS score of 9.8.
Versions 19.1, 19.2, and 19.3 of Dell EMC Avamar Server are affected by CVE-2020-29493.
A remote unauthenticated attacker can potentially exploit CVE-2020-29493 by executing certain SQL commands on the application's backend database.
CVE-2020-29493 can lead to unauthorized access and execution of SQL commands on the application's backend database.
Yes, Dell has released a security update for CVE-2020-29493. Please refer to the following link for more information: https://www.dell.com/support/kbdoc/en-us/000181806/dsa-2020-272-dell-emc-avamar-server-security-update-for-multiple-vulnerabilities