Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11048


Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain system files in the server or cause denial of service by supplying specially crafted Document Type Definitions (DTDs) in an XML request.


Published

2018-08-10T20:29:00.243

Last Modified

2024-11-21T03:42:33.787

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_data_protection_advisor 6.2 Yes
Application dell emc_data_protection_advisor 6.3 Yes
Application dell emc_data_protection_advisor 6.4 Yes
Application dell emc_data_protection_advisor 6.5 Yes
Application dell emc_integrated_data_protection_appliance 2.0 Yes
Application dell emc_integrated_data_protection_appliance 2.1 Yes

References