CVE-2024-47484 HIGH

CVE-2024-47484

Vendor Dell
Product Avamar
Weakness CWE-89 · SQLi
Published December 10, 2024
Last update August 4, 2025

CVSS base score

8.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

What the vulnerability does

01Description

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

Key dates

02Disclosure timeline

December 10, 2024 CVE published
August 4, 2025 Record updated