CVE-2019-18581

moderate-risk
Published 2020-03-18

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.

Do I need to act?

~
2.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10 High
NETWORK / LOW complexity

Affected Products (11)

Emc Data Protection Advisor
Emc Data Protection Advisor
Emc Data Protection Advisor
Emc Data Protection Advisor
Emc Data Protection Advisor
Emc Data Protection Advisor
Emc Integrated Data Protection Appliance Firmware
Emc Integrated Data Protection Appliance Firmware
Emc Integrated Data Protection Appliance Firmware
Emc Integrated Data Protection Appliance Firmware
Emc Integrated Data Protection Appliance Firmware

Affected Vendors

47
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 5/34 · Minimal
Exposure 16/34 · Moderate