Dell EMC Update
3071Warning Date
Severity Level
Warning Number
Target Sector
8 September, 2019
● High
2019-512
All
Description:
Dell EMC has released security update to address a vulnerability in following products:
- Dell EMC Avamar Server Versions: 7.4.1, 7.5.0, 7.5.1, 18.2, and 19.1
- Dell EMC Integrated Data Protection Appliance (IDPA) Versions 2.0, 2.1, 2.2, 2.3, and 2.4
Threats:
Remote attacker could exploit this vulnerability by causing a denial of service attack (DoS) or an information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.
Best practice and Recommendations:
The CERT team encourages users to review Dell EMC security advisory and apply the necessary updates: https://www.dell.com/support/security/en-us/details/537853/DSA-2019-119-Dell-EMC-Avamar-XML-External-Entity-Injection-Vulnerability