CVE-2018-11067 describes an open redirection vulnerability in Dell EMC Avamar Client Manager across multiple Avamar Server and Integrated Data Protection Appliance versions. This flaw allows a remote, unauthenticated attacker to redirect users to arbitrary malicious websites via crafted links. The vulnerability carries a CVSS score of 6.1 (Medium), indicating a low attack complexity and no authentication required, but relies on user interaction. Successful exploitation could lead to phishing attacks, compromising user confidentiality and integrity. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public awareness or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2.0CPE matchmatch criteria | cpe:2.3:a:dell:emc_avamar:7.2.0:*:*:*:*:*:*:* | ||
7.2.1CPE matchmatch criteria | cpe:2.3:a:dell:emc_avamar:7.2.1:*:*:*:*:*:*:* | ||
7.3.0CPE matchmatch criteria | cpe:2.3:a:dell:emc_avamar:7.3.0:*:*:*:*:*:*:* | ||
7.3.1CPE matchmatch criteria | cpe:2.3:a:dell:emc_avamar:7.3.1:*:*:*:*:*:*:* | ||
7.4.0CPE matchmatch criteria | cpe:2.3:a:dell:emc_avamar:7.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.