First published: Mon Apr 13 2020(Updated: )
An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rubrik Cloud Data Management | >=5.0.0<=5.0.4 | |
Rubrik Cloud Data Management | >=5.1.0<5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9478 is an OS command injection vulnerability in Rubrik 5.0.3-2296.
An attacker can exploit CVE-2020-9478 by sending malicious input to a vulnerable Rubrik-managed system, allowing them to execute arbitrary code.
CVE-2020-9478 has a severity rating of 8.8, which is considered critical.
Versions between 5.0.0 and 5.0.4, as well as versions between 5.1.0 and 5.1.2 of Rubrik CDM are affected by CVE-2020-9478.
To mitigate CVE-2020-9478, it is recommended to update to a fixed version of Rubrik CDM, as specified in the advisory provided by Rubrik.