SB2020031833 - Multiple vulnerabilities in Dell EMC Data Protection Advisor



SB2020031833 - Multiple vulnerabilities in Dell EMC Data Protection Advisor

Published: March 18, 2020 Updated: August 8, 2020

Security Bulletin ID SB2020031833
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Missing Authorization (CVE-ID: CVE-2019-18581)

The vulnerability allows a remote privileged user to execute arbitrary code.

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.


2) Code Injection (CVE-ID: CVE-2019-18582)

The vulnerability allows a remote privileged user to execute arbitrary code.

Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server. This may lead to OS command execution as the regular user runs the DPA service on the affected system.


Remediation

Install update from vendor's website.