Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-52538


Dell Avamar, version(s) 19.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.


Published

2024-12-10T11:15:07.690

Last Modified

2025-02-04T16:12:55.947

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.6 (HIGH)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell avamar_server 19.4 Yes
Application dell avamar_server 19.7 Yes
Application dell avamar_server 19.8 Yes
Application dell avamar_server 19.9 Yes
Application dell avamar_server 19.10 Yes
Application dell avamar_server 19.10 Yes
Hardware dell avamar_data_store gen4t No
Hardware dell avamar_data_store gen5a No

References