CVE-2020-29495

Severity
10.0CRITICAL
EPSS
15.5%
top 5.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 24

Description

DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This vulnerability is considered critical as it can be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgra

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages3 packages

NVDdell/emc_avamar_server19.1, 19.2, 19.3+2
CVEListV5dell/avamarunspecifiedHF 19.1, 19.2, 19.3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q9fj-r59w-qgwr: DELL EMC Avamar Server, versions 192022-05-24
CVEList
CVE-2020-29495: DELL EMC Avamar Server, versions 192021-01-14