Description
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.
Published: 2020-03-18
Score: 7.2 High
EPSS: 2.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-8328 Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.
History

No history.

Subscriptions

Dell Emc Data Protection Advisor Emc Idpa Dp4400 Emc Idpa Dp5800 Emc Idpa Dp8300 Emc Idpa Dp8800 Emc Integrated Data Protection Appliance Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T23:01:47.466Z

Reserved: 2019-10-29T00:00:00.000Z

Link: CVE-2019-18581

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-18T19:15:16.497

Modified: 2024-11-21T04:33:20.340

Link: CVE-2019-18581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses