CVE-2019-18581
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.
Published:Mar 18, 2020
Last Modified:Nov 21, 2024
EPS:Mar 18, 2020
EPSS Score:0.02202
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Dell
Product
Emc Data Protection Advisor
Dell
Emc Data Protection Advisor
Vendor
Dell
Product
Emc Idpa Dp4400
Dell
Emc Idpa Dp4400
Vendor
Dell
Product
Emc Idpa Dp5800
Dell
Emc Idpa Dp5800
Vendor
Dell
Product
Emc Idpa Dp8300
Dell
Emc Idpa Dp8300
Vendor
Dell
Product
Emc Idpa Dp8800
Dell
Emc Idpa Dp8800
Vendor
Dell
Product
Emc Integrated Data Protection Appliance Firmware
Dell
Emc Integrated Data Protection Appliance Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
