CVE-2018-11066

3 documents3 sources
Severity
9.8CRITICAL
EPSS
41.0%
top 2.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateMay 13

Description

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary commands on the server.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

CVEListV5dell_emc/avamar9 versions+8
NVDdell/emc_avamar9 versions+8
NVDvmware/vsphere_data_protection19 versions+18

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m593-g9cm-c9fm: Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 72022-05-13
CVEList
Dell EMC Avamar and Integrated Data Protection Appliance Remote Code Execution Vulnerability2018-11-26