CVE-2024-52538: SQL Injection
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52538?
CVE-2024-52538 is categorized as a low severity vulnerability.
How do I fix CVE-2024-52538?
To fix CVE-2024-52538, update Dell Avamar to the latest patched version as specified in official Dell security updates.
What types of attacks can exploit CVE-2024-52538?
CVE-2024-52538 can be exploited by low privileged attackers to perform SQL injection attacks.
Which versions of Dell Avamar are affected by CVE-2024-52538?
CVE-2024-52538 affects Dell Avamar versions 19.0 through 19.10-sp1.
Does CVE-2024-52538 allow remote access exploitation?
Yes, CVE-2024-52538 allows low privileged attackers to potentially exploit the vulnerability remotely.