CVE-2019-3765: Dell Emc Avamar Server

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4 contain an Incorrect Permission Assignment for Critical Resource vulnerability. A remote authenticated malicious user potentially could exploit this vulnerability to view or modify sensitive backup data. This could be used to make backups corrupt or potentially to trick a user into restoring a backup with malicious files in place.

Affected products

  • Dell Emc Avamar Server: version 7.4.1 only; version 7.5.0 only; version 7.5.1 only; version 18.2 only; version 19.1 only
  • Dell Emc Integrated Data Protection Appliance: from 2.0, up to and including 2.4

Published 2019-10-09. Last modified 2026-06-17.