CVE-2018-11076
moderate-risk
Published 2018-11-26
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private key could potentially be used by an unauthenticated attacker on the same data-link layer to initiate a MITM attack on management console users.
Do I need to act?
-
0.39% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10
Medium
ADJACENT_NETWORK
/ LOW complexity
Affected Products (20)
References (8)
Third Party Advisory
http://www.securityfocus.com/bid/105972
Third Party Advisory
http://www.securitytracker.com/id/1042153
Mailing List
https://seclists.org/fulldisclosure/2018/Nov/50
Third Party Advisory
http://www.securityfocus.com/bid/105972
Third Party Advisory
http://www.securitytracker.com/id/1042153
Mailing List
https://seclists.org/fulldisclosure/2018/Nov/50
43
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
1/34 · Minimal
Exposure
21/34 · High