CVE-2024-52538

HIGH

Dell Avamar < 19.12 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

Scores

CVSS v3 7.6
EPSS 0.0027
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (5)
dell/avamar_server 19.4
dell/avamar_server 19.7
dell/avamar_server 19.8
dell/avamar_server 19.9
dell/avamar_server 19.10 (2 CPE variants)
Published Dec 10, 2024
Tracked Since Feb 18, 2026