Vulnerability CVE-2018-11077


Published: 2018-11-26

Description:
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Vmware -> Vsphere data protection 
DELL -> Emc avamar 
DELL -> Emc integrated data protection appliance 

 References:
http://www.securityfocus.com/bid/105971
http://www.securitytracker.com/id/1042153
https://seclists.org/fulldisclosure/2018/Nov/51
https://www.vmware.com/security/advisories/VMSA-2018-0029.html

Copyright 2020, cxsecurity.com

 

Back to Top