Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-52538


Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.


Published

2024-12-10T11:15:07.690

Last Modified

2025-08-04T19:15:30.007

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell avamar_server 19.4 Yes
Application dell avamar_server 19.7 Yes
Application dell avamar_server 19.8 Yes
Application dell avamar_server 19.9 Yes
Application dell avamar_server 19.10 Yes
Application dell avamar_server 19.10 Yes
Hardware dell avamar_data_store gen4t No
Hardware dell avamar_data_store gen5a No

References