CVE-2024-52538
Last modified
CVE-2024-52538 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Avamar Server | 19.4 |
| Dell | Avamar Server | 19.7 |
| Dell | Avamar Server | 19.8 |
| Dell | Avamar Server | 19.9 |
| Dell | Avamar Server | 19.10 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-52538?
How severe is CVE-2024-52538?
How do I fix CVE-2024-52538?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52531GNOME libsoup before 3.6.1 allows a buffer overflow in appli…6.5
- CVE-2024-52532GNOME libsoup before 3.6.1 has an infinite loop, and memory …7.5
- CVE-2024-52533gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-b…9.8
- CVE-2024-52534Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Aut…5.4
- CVE-2024-52535Dell SupportAssist for Home PCs versions 4.6.1 and prior and…8.8
- CVE-2024-52537Dell Client Platform Firmware Update Utility contains an Imp…6.7
- CVE-2024-5254The Ultimate Addons for WPBakery plugin for WordPress is vul…5.4
- CVE-2024-52541Dell Client Platform BIOS contains a Weak Authentication vul…8.2
- CVE-2024-52542Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Syml…5.5
- CVE-2024-52543Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation o…4.4
- CVE-2024-52544An unauthenticated attacker can trigger a stack based buffer…9.8
- CVE-2024-52545An unauthenticated attacker can perform an out of bounds hea…6.5
Are you affected by CVE-2024-52538?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
