Server Authorization Flaw in Dell EMC Data Protection Advisor
CVE-2019-18581

9.1CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
18 March 2020

Summary

A server-side authorization vulnerability exists in Dell EMC Data Protection Advisor that affects versions 6.3, 6.4, 6.5, and 18.2 prior to patch 83, as well as 19.1 prior to patch 71. This vulnerability enables a remote authenticated attacker with administrative access to manipulate the application's command execution policy. By exploiting this issue, the attacker may gain the ability to execute arbitrary OS commands under the context of the DPA service, potentially compromising the security and integrity of the system.

Affected Version(s)

Data Protection Advisor < 6.3, 6.4, 6.5 and version prior to 18.2 patch 83 and prior to 19.1 patch 71

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.