CVE-2020-29494

CWE-22Path Traversal3 documents3 sources
Severity
8.7HIGH
EPSS
0.9%
top 23.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 24

Description

Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the arbitrary files stored on the server filesystem, causing deletion of arbitrary files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:HExploitability: 2.3 | Impact: 5.8

Affected Packages3 packages

NVDdell/emc_avamar_server19.1, 19.2, 19.3+2
CVEListV5dell/avamarunspecifiedHF 19.1, 19.2, 19.3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xjxp-x9rc-crcf: Dell EMC Avamar Server, versions 192022-05-24
CVEList
CVE-2020-29494: Dell EMC Avamar Server, versions 192021-01-14