Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-29495


DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This vulnerability is considered critical as it can be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.


Published

2021-01-14T21:15:13.600

Last Modified

2024-11-21T05:24:06.830

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell emc_avamar_server 19.1 Yes
Application dell emc_avamar_server 19.2 Yes
Application dell emc_avamar_server 19.3 Yes
Application dell emc_integrated_data_protection_appliance 2.5 Yes
Application dell emc_integrated_data_protection_appliance 2.6 Yes

References