OS Command Injection Vulnerability in Dell EMC Avamar Server and Integrated Data Protection Appliance

OS Command Injection Vulnerability in Dell EMC Avamar Server and Integrated Data Protection Appliance

CVE-2018-11077 · HIGH Severity

AV:L/AC:L/AU:N/C:C/I:C/A:C

'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.

Learn more about our Cis Benchmark Audit For Server Software.