ZDI-24-1693: Dell Avamar Web Restore Login Action SQL Injection Information Disclosure Vulnerability
Published Dec 16, 2024
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dell Avamar. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2024-47484.
Affected Software
1 affected component
Dell Avamar
Event History
Dec 16, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1693?
The severity of ZDI-24-1693 is rated at 8.2 on the CVSS scale.
2
How does ZDI-24-1693 allow for exploitation?
ZDI-24-1693 allows remote attackers to disclose sensitive information without requiring authentication.
3
Which software is affected by ZDI-24-1693?
ZDI-24-1693 affects Dell Avamar installations.
4
What is the CVE associated with ZDI-24-1693?
The CVE associated with ZDI-24-1693 is CVE-2024-47484.
5
Are there any specific mitigation steps for ZDI-24-1693?
Mitigating ZDI-24-1693 typically involves applying security patches provided by Dell.