← Vulnerability feed

Vulnerability record · CVE-2018-1217 · published 9 April 2018

CVE-2018-1217: Dell EMC Avamar Installation Manager missing access control exposes LDLS credentials

Dell · Emc Avamar

Dell EMC Avamar Server and Integrated Data Protection Appliance contain a missing access control check in Avamar Installation Manager. A remote unauthenticated attacker can read or modify the Local Download Service (LDLS) credentials used to connect to Dell EMC Online Support. Because those credentials can be used to impersonate AVI service actions, the flaw exposes both sensitive credential material and the integrity of the support connection.

9.8 CVSS 3.0 Critical EPSS 51% · top 1.1% CWE-862 · Missing authorization
9.8CVSS 3.0 base score, v2 5.0
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or change the Local Download Service (LDLS) credentials. The LDLS credentials are used to connect to Dell EMC Online Support. If the LDLS configuration was changed to an invalid configuration, then Avamar Installation Manager may not be able to connect to Dell EMC Online Support web site successfully. The remote unauthenticated attacker can also read and use the credentials to login to Dell EMC Online Support, impersonating the AVI service actions using those credentials.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, high EPSS, and public exploit code make this a high-risk, remotely exploitable credential exposure.

What it is

Dell EMC Avamar Server and Integrated Data Protection Appliance contain a missing access control check in Avamar Installation Manager. A remote unauthenticated attacker can read or modify the Local Download Service (LDLS) credentials used to connect to Dell EMC Online Support. Because those credentials can be used to impersonate AVI service actions, the flaw exposes both sensitive credential material and the integrity of the support connection.

Impact

An attacker gains read and write access to LDLS credentials, allowing them to log in to Dell EMC Online Support and impersonate AVI service actions. They can also corrupt the LDLS configuration so the appliance can no longer reach Dell EMC Online Support.

Attack surface

The vulnerability is network-reachable with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. It is exposed through the Avamar Installation Manager interface.

Exploitation

No CISA KEV listing is present, but EPSS is 0.50874 (98.874th percentile) and a public Exploit-DB entry (44441) exists, indicating exploit code is available and exploitation is plausible.

What to do

  • Apply the Dell EMC vendor fix for Avamar Server 7.3.1, 7.4.1, 7.5.0 and Integrated Data Protection Appliance 2.0/2.1 as soon as possible.
  • Restrict network access to Avamar Installation Manager to trusted management networks only.
  • Rotate the LDLS credentials and any Dell EMC Online Support credentials that may have been exposed.
  • Verify the LDLS configuration is valid and that the appliance can still reach Dell EMC Online Support after remediation.
  • Monitor for unauthorized changes to LDLS settings or unexpected Dell EMC Online Support logins.

Detection

  • Review Avamar Installation Manager access logs for unauthenticated requests to LDLS credential or configuration endpoints.
  • Alert on changes to LDLS configuration or credential values outside approved maintenance windows.
  • Monitor Dell EMC Online Support authentication logs for logins originating from unexpected sources or using AVI service credentials.
  • Hunt for use of the public Exploit-DB 44441 proof-of-concept against exposed Avamar Installation Manager instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2018/Apr/14 Mailing ListThird Party Advisory
http://www.securitytracker.com/id/1040641 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44441/ ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2018/Apr/14 Mailing ListThird Party Advisory
http://www.securitytracker.com/id/1040641 Third Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/44441/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2018-1217 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-29495Dell emc avamar server path traversal vulnerabilityDELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attack…EPSS 6.2%9.8CVE-2020-29493Dell emc avamar server sql injection vulnerabilityDELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a SQL Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could…EPSS 2.6%9.8CVE-2018-11066Dell emc avamar vulnerabilityDell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrate…EPSS 9.9%8.8CVE-2018-11062Dell emc integrated data protection appliance hard-coded credentials vulnerabilityIntegrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with def…EPSS 1.8%8.7CVE-2020-29494Dell emc avamar server path traversal vulnerabilityDell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulner…EPSS 1.7%8.2CVE-2019-3752Dell emc avamar server xml external entity (xxe) vulnerabilityDell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2…EPSS 0.98%8.1CVE-2021-21511Dell emc avamar server improper authorization vulnerabilityDell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote low privileged attacker could …EPSS 1.0%8.1CVE-2019-3765Dell emc avamar server incorrect permission assignment vulnerabilityDell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-1217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.