CVE-2021-36316 MEDIUM

CVE-2021-36316

Vendor Dell
Product Avamar
Weakness CWE-269
Published December 21, 2021
Last update September 16, 2024

CVSS base score

6.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H

What the vulnerability does

01Description

Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious user with high privileges could potentially exploit this vulnerability, leading to the disclosure of the AUI info and performing some unauthorized operation on the AUI.

Key dates

02Disclosure timeline

December 21, 2021 CVE published
September 16, 2024 Record updated