CVE-2020-9478: Command Injection
Published Apr 13, 2020
·Updated
An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems.
Affected Software
2 affected components
Rubrik CDM>=5.0.0<=5.0.4
Rubrik CDM>=5.1.0<5.1.2
Event History
Apr 13, 2020
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 15, 58461
Event
04:20 PM
Frequently Asked Questions
1
What is CVE-2020-9478?
CVE-2020-9478 is an OS command injection vulnerability in Rubrik 5.0.3-2296.
2
How can an attacker exploit CVE-2020-9478?
An attacker can exploit CVE-2020-9478 by sending malicious input to a vulnerable Rubrik-managed system, allowing them to execute arbitrary code.
3
What is the severity of CVE-2020-9478?
CVE-2020-9478 has a severity rating of 8.8, which is considered critical.
4
Which versions of Rubrik CDM are affected by CVE-2020-9478?
Versions between 5.0.0 and 5.0.4, as well as versions between 5.1.0 and 5.1.2 of Rubrik CDM are affected by CVE-2020-9478.
5
How do I mitigate CVE-2020-9478?
To mitigate CVE-2020-9478, it is recommended to update to a fixed version of Rubrik CDM, as specified in the advisory provided by Rubrik.