First published: Mon Feb 15 2021(Updated: )
Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could potentially exploit this vulnerability, to gain unauthorized read or modification access to other users' backup data.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Avamar Server | =19.3 | |
Dell EMC Avamar Server | =19.4 | |
Dell EMC Integrated Data Protection Appliance | =2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21511 is a vulnerability in Dell EMC Avamar Server versions 19.3 and 19.4 that allows a remote attacker to gain unauthorized read or modification access to other users' backup data.
CVE-2021-21511 has a severity score of 8.1, which is considered high.
CVE-2021-21511 affects Dell EMC Avamar Server versions 19.3 and 19.4, allowing a remote low privileged attacker to gain unauthorized access to backup data.
Yes, Dell EMC has released a fix for CVE-2021-21511. It is recommended to update to the latest version of Dell EMC Avamar Server or refer to the official Dell support article for more information.
More information about CVE-2021-21511 can be found in the official Dell support article at the following link: [Dell Support Article](https://www.dell.com/support/kbdoc/en-us/000182926/dsa-2021-033-dell-emc-avamar-server-improper-authorization-vulnerability)