Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-11077


'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.


Published

2018-11-26T20:29:00.420

Last Modified

2024-11-21T03:42:38.010

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_avamar 7.2.0 Yes
Application dell emc_avamar 7.2.1 Yes
Application dell emc_avamar 7.3.0 Yes
Application dell emc_avamar 7.3.1 Yes
Application dell emc_avamar 7.4.0 Yes
Application dell emc_avamar 7.4.1 Yes
Application dell emc_avamar 7.5.0 Yes
Application dell emc_avamar 7.5.1 Yes
Application dell emc_avamar 18.1 Yes
Application dell emc_integrated_data_protection_appliance 2.0 Yes
Application dell emc_integrated_data_protection_appliance 2.1 Yes
Application dell emc_integrated_data_protection_appliance 2.2 Yes
Application vmware vsphere_data_protection 6.0.0 Yes
Application vmware vsphere_data_protection 6.0.1 Yes
Application vmware vsphere_data_protection 6.0.2 Yes
Application vmware vsphere_data_protection 6.0.3 Yes
Application vmware vsphere_data_protection 6.0.4 Yes
Application vmware vsphere_data_protection 6.0.5 Yes
Application vmware vsphere_data_protection 6.0.6 Yes
Application vmware vsphere_data_protection 6.0.7 Yes
Application vmware vsphere_data_protection 6.0.8 Yes
Application vmware vsphere_data_protection 6.1.0 Yes
Application vmware vsphere_data_protection 6.1.1 Yes
Application vmware vsphere_data_protection 6.1.2 Yes
Application vmware vsphere_data_protection 6.1.3 Yes
Application vmware vsphere_data_protection 6.1.4 Yes
Application vmware vsphere_data_protection 6.1.5 Yes
Application vmware vsphere_data_protection 6.1.6 Yes
Application vmware vsphere_data_protection 6.1.7 Yes
Application vmware vsphere_data_protection 6.1.8 Yes
Application vmware vsphere_data_protection 6.1.9 Yes

References