Dell EMC Avamar Security Update for ADMe Web UI Vulnerability
CVE-2019-3737
8.6HIGH
Summary
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application.
Affected Version(s)
Avamar ADMe Web UI 1.0.50
Avamar ADMe Web UI 1.0.51
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell EMC would like to thank Ken Pyle from DFDR Consulting for reporting this vulnerability.