Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-29493


DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.


Published

2021-01-14T21:15:13.397

Last Modified

2024-11-21T05:24:06.510

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_avamar_server 19.1 Yes
Application dell emc_avamar_server 19.2 Yes
Application dell emc_avamar_server 19.3 Yes
Application dell emc_integrated_data_protection_appliance 2.5 Yes
Application dell emc_integrated_data_protection_appliance 2.6 Yes

References