HIGH✓ PATCH🇬🇧 English

CVE-2020-29494

CVSS 8.7v3.1pub. 2021-01-14upd. 2024-11-21

Dell EMC Avamar Server, versions 19.1, 19.2, 19.3, contain a Path Traversal Vulnerability in PDM. A remote user could potentially exploit this vulnerability, to gain unauthorized write access to the arbitrary files stored on the server filesystem, causing deletion of arbitrary files.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
  • Dell Emc Avamar Server

    APP
    Dell
    19.119.219.3
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    2.52.6
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Path Traversal
CWE
Referencje

Powiązane podatności

CVE-2020-5341CRITICAL9.8PL ✓ten sam produkt

RCE poprzez Deserialization w Dell EMC Avamar Server i IDPA

CVE-2020-29495CRITICAL10.0PL ✓ten sam produkt

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2020-29493CRITICAL10.0PL ✓ten sam produkt

SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych

CVE-2018-11066CRITICAL9.8PL ✓ten sam produkt

RCE w Dell EMC Avamar Client Manager — zdalny dostęp bez uwierzytelnienia

CVE-2018-1217CRITICAL9.8PL ✓ten sam produkt

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających