Server-Side Template Injection in Dell EMC Data Protection Advisor Products
CVE-2019-18582

9.1CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
18 March 2020

Summary

The server-side template injection vulnerability in Dell EMC Data Protection Advisor's REST API allows a remote authenticated user with administrative privileges to inject malicious scripts. This exploitation could lead to OS command execution, as the DPA service operates under the context of a regular user on the affected system. Patch updates are critical to mitigating this risk.

Affected Version(s)

Data Protection Advisor < 6.3, 6.4, 6.5 and version prior to 18.2 patch 83 and prior to 19.1 patch 71

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.