Dell EMC Update
3099Warning Date
Severity Level
Warning Number
Target Sector
6 October, 2019
● High
2019-487
All
Description:
Dell has released security update to address multiple vulnerabilities in the following product:
- Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, and 19.1
- Dell EMC Integrated Data Protection Appliance (IDPA) 2.0, 2.1, 2.2, 2.3, and 2.4.
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- View sensitive backup data.
- Modify sensitive backup data.
Best Practice and Recommendations:
The CERT team encourages users to review Dell security advisory and apply the necessary updates: https://www.dell.com/support/security/en-us/details/537649/DSA-2019-138-Dell-EMC-Avamar-Incorrect-Permission-Assignment-for-Critical-Resource-Vulnerability