CVE-2018-11077OS Command Injection in EMC Avamar

Severity
6.7MEDIUMNVD
EPSS
0.4%
top 41.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateMay 14

Description

'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5dell_emc/avamar9 versions+8
NVDdell/emc_avamar9 versions+8
NVDvmware/vsphere_data_protection19 versions+18

Patches

🔴Vulnerability Details

2
GHSA
GHSA-53fw-rm7m-jqgv: 'getlogs' utility in Dell EMC Avamar Server versions 72022-05-14
CVEList
Dell EMC Avamar and Integrated Data Protection Appliance Command Injection Vulnerability2018-11-26
CVE-2018-11077 — OS Command Injection in EMC Avamar | cvebase