CVE-2018-11067
moderate-risk
Published 2018-11-26
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.
Do I need to act?
-
0.51% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.1/10
Medium
NETWORK
/ LOW complexity
Affected Products (20)
References (8)
Third Party Advisory
http://www.securityfocus.com/bid/105969
Third Party Advisory
http://www.securitytracker.com/id/1042153
Mailing List
https://seclists.org/fulldisclosure/2018/Nov/49
Third Party Advisory
http://www.securityfocus.com/bid/105969
Third Party Advisory
http://www.securitytracker.com/id/1042153
Mailing List
https://seclists.org/fulldisclosure/2018/Nov/49
48
/ 100
moderate-risk
Severity
23/34 · High
Exploitability
2/34 · Minimal
Exposure
23/34 · High