Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-1217Missing Authorization in Dell EMC Avamar

Severity
9.8CRITICALNVD
EPSS
65.9%
top 1.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 9
Latest updateMay 13

Description

Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDdell/emc_avamar7.3.1, 7.4.1, 7.5.0+2

🔴Vulnerability Details

3
GHSA
GHSA-6583-rv3q-95pf: Avamar Installation Manager in Dell EMC Avamar Server 72022-05-13
CVEList
CVE-2018-1217: Avamar Installation Manager in Dell EMC Avamar Server 72018-04-09
VulnCheck
dell emc_avamar Missing Authorization2018

💥Exploits & PoCs

2
Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control2018-04-10
Nuclei
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
CVE-2018-1217 — Missing Authorization in Dell | cvebase