Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar Java management console's SSL/TLS private key may be leaked in the Avamar Java management client package. The private key could potentially be used by an unauthenticated attacker on the same data-link layer to initiate a MITM attack on management console users.
References
Link Resource
http://www.securityfocus.com/bid/105972 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1042153 Third Party Advisory VDB Entry
https://seclists.org/fulldisclosure/2018/Nov/50 Mailing List Third Party Advisory
https://www.vmware.com/security/advisories/VMSA-2018-0029.html Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2018-11-20T00:00:00

Updated: 2018-11-27T16:57:01

Reserved: 2018-05-14T00:00:00


Link: CVE-2018-11076

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-11-26T20:29:00.357

Modified: 2020-08-24T17:37:01.140


Link: CVE-2018-11076

JSON object: View

cve-icon Redhat Information

No data.