CVE-2020-29493

CRITICAL

DELL EMC Avamar Server <19.3 - SQL Injection

Title source: llm
STIX 2.1

Description

DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.

Scores

CVSS v3 10.0
EPSS 0.0580
EPSS Percentile 90.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (5)
dell/emc_avamar_server 19.1
dell/emc_avamar_server 19.2
dell/emc_avamar_server 19.3
dell/emc_integrated_data_protection_appliance 2.5
dell/emc_integrated_data_protection_appliance 2.6
Published Jan 14, 2021
Tracked Since Feb 18, 2026