Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3752


Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause Denial of Service or information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.


Published

2021-07-16T22:15:07.757

Last Modified

2024-11-21T04:42:27.913

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-611
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_avamar_server 7.4.1 Yes
Application dell emc_avamar_server 7.5.0 Yes
Application dell emc_avamar_server 7.5.1 Yes
Application dell emc_avamar_server 18.2 Yes
Application dell emc_avamar_server 19.1 Yes
Application dell emc_integrated_data_protection_appliance 2.0 Yes
Application dell emc_integrated_data_protection_appliance 2.1 Yes
Application dell emc_integrated_data_protection_appliance 2.2 Yes
Application dell emc_integrated_data_protection_appliance 2.3 Yes
Application dell emc_integrated_data_protection_appliance 2.4 Yes

References