7.2
CVSSv2

CVE-2018-11077

Published: 26/11/2018 Updated: 31/12/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dell emc avamar 7.4.1

dell emc avamar 7.3.1

dell emc avamar 7.3.0

dell emc avamar 7.2.0

dell emc avamar 7.2.1

dell emc integrated data protection appliance 2.2

dell emc integrated data protection appliance 2.0

dell emc avamar 18.1

dell emc avamar 7.5.1

dell emc integrated data protection appliance 2.1

dell emc avamar 7.5.0

dell emc avamar 7.4.0

vmware vsphere data protection 6.0.0

vmware vsphere data protection 6.0.2

vmware vsphere data protection 6.0.4

vmware vsphere data protection 6.1.0

vmware vsphere data protection 6.1.2

vmware vsphere data protection 6.1.9

vmware vsphere data protection 6.1.4

vmware vsphere data protection 6.1.5

vmware vsphere data protection 6.1.6

vmware vsphere data protection 6.1.7

vmware vsphere data protection 6.0.5

vmware vsphere data protection 6.0.6

vmware vsphere data protection 6.0.7

vmware vsphere data protection 6.0.8

vmware vsphere data protection 6.0.1

vmware vsphere data protection 6.0.3

vmware vsphere data protection 6.1.1

vmware vsphere data protection 6.1.3

vmware vsphere data protection 6.1.8