CVE-2018-11077: Dell EMC Avamar and Integrated Data Protection Appliance Command Injection Vulnerability
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2018-11077.
Which software versions are affected by this vulnerability?
The affected software versions are Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, and 2.2.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is high with a CVSS score of 6.7.
What is the CVE ID of the vulnerability that addresses this issue?
There is no specific CVE ID for the fix, but the issue is addressed in the affected software versions.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the following websites: SecurityFocus (http://www.securityfocus.com/bid/105971), SecurityTracker (http://www.securitytracker.com/id/1042153), and Full Disclosure mailing list (https://seclists.org/fulldisclosure/2018/Nov/51).