Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.
| Software | From | Fixed in |
|---|---|---|
| dell / avamar_server | 19.10-sp1 | 19.10-sp1.x |
| dell / avamar_server | 19.4 | 19.4.x |
| dell / avamar_server | 19.7 | 19.7.x |
| dell / avamar_server | 19.8 | 19.8.x |
| dell / avamar_server | 19.9 | 19.9.x |
| dell / avamar_server | 19.10 | 19.10.x |