CVE-2018-11076
Last modified
CVE-2018-11076 is a vulnerability of currently unknown severity. Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private key could potentially be used by an unauthenticated attacker on the same data-link layer to initiate a MITM attack on management console users.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Emc Avamar | 7.2.0 |
| Dell | Emc Avamar | 7.2.1 |
| Dell | Emc Avamar | 7.3.0 |
| Dell | Emc Avamar | 7.3.1 |
| Dell | Emc Avamar | 7.4.0 |
| Dell | Emc Avamar | 7.4.1 |
| Dell | Emc Integrated Data Protection Appliance | 2.0 |
| Vmware | Vsphere Data Protection | 6.0.0 |
| Vmware | Vsphere Data Protection | 6.0.1 |
| Vmware | Vsphere Data Protection | 6.0.2 |
| Vmware | Vsphere Data Protection | 6.0.3 |
| Vmware | Vsphere Data Protection | 6.0.4 |
| Vmware | Vsphere Data Protection | 6.0.5 |
| Vmware | Vsphere Data Protection | 6.0.6 |
| Vmware | Vsphere Data Protection | 6.0.7 |
| Vmware | Vsphere Data Protection | 6.0.8 |
| Vmware | Vsphere Data Protection | 6.1.0 |
| Vmware | Vsphere Data Protection | 6.1.1 |
| Vmware | Vsphere Data Protection | 6.1.2 |
| Vmware | Vsphere Data Protection | 6.1.3 |
| Vmware | Vsphere Data Protection | 6.1.4 |
| Vmware | Vsphere Data Protection | 6.1.5 |
| Vmware | Vsphere Data Protection | 6.1.6 |
| Vmware | Vsphere Data Protection | 6.1.7 |
| Vmware | Vsphere Data Protection | 6.1.8 |
| Vmware | Vsphere Data Protection | 6.1.9 |
References
- http://www.securityfocus.com/bid/105972Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042153Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Nov/50Mailing List, Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2018-0029.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/105972Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042153Third Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2018/Nov/50Mailing List, Third Party Advisory
- https://www.vmware.com/security/advisories/VMSA-2018-0029.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11076?
How severe is CVE-2018-11076?
How do I fix CVE-2018-11076?
Are you affected by CVE-2018-11076?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
