CVE-2019-3752
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4. contain an XML External Entity(XXE) Injection vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability to cause Denial of Service or information exposure by supplying specially crafted document type definitions (DTDs) in an XML request.
Dell EMC Avamar Server versiones 7.4.1, 7.5.0, 7.5.1, 18.2 y 19.1 de y Dell EMC Integrated Data Protection Appliance (IDPA) versiones 2.0, 2.1, 2.2, 2.3 y 2.4, contienen una vulnerabilidad de tipo XML External Entity(XXE). Un usuario remoto malicioso no autenticado podría potencialmente explotar esta vulnerabilidad para causar una Denegación de Servicio o la exposición de información al suministrar definiciones de tipo de documento (DTD) especialmente diseñadas en una petición XML
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2021-07-16 CVE Published
- 2024-02-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/security/en-us/details/537853/DSA-2019-119-Dell-EMC-Avamar-XML-External-Entity-Injection-Vulnerability | 2021-07-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Emc Avamar Server Search vendor "Dell" for product "Emc Avamar Server" | 7.4.1 Search vendor "Dell" for product "Emc Avamar Server" and version "7.4.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Avamar Server Search vendor "Dell" for product "Emc Avamar Server" | 7.5.0 Search vendor "Dell" for product "Emc Avamar Server" and version "7.5.0" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Avamar Server Search vendor "Dell" for product "Emc Avamar Server" | 7.5.1 Search vendor "Dell" for product "Emc Avamar Server" and version "7.5.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Avamar Server Search vendor "Dell" for product "Emc Avamar Server" | 18.2 Search vendor "Dell" for product "Emc Avamar Server" and version "18.2" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Avamar Server Search vendor "Dell" for product "Emc Avamar Server" | 19.1 Search vendor "Dell" for product "Emc Avamar Server" and version "19.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Integrated Data Protection Appliance Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" | 2.0 Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" and version "2.0" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Integrated Data Protection Appliance Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" | 2.1 Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" and version "2.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Integrated Data Protection Appliance Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" | 2.2 Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" and version "2.2" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Integrated Data Protection Appliance Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" | 2.3 Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" and version "2.3" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Emc Integrated Data Protection Appliance Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" | 2.4 Search vendor "Dell" for product "Emc Integrated Data Protection Appliance" and version "2.4" | - |
Affected
|