CRITICAL🇵🇱 Wersja polska

CVE-2018-11066

CVSS 9.8v3.0pub. 2018-11-26upd. 2024-11-21

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary commands on the server.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Emc Avamar

    APP
    Dell
    18.17.2.07.2.17.3.07.3.17.4.07.4.17.5.07.5.1
  • Dell Emc Integrated Data Protection Appliance

    APP
    Dell
    2.02.12.2
  • VMware vSphere Data Protection

    APP
    Vmware
    6.0.06.0.16.0.26.0.36.0.46.0.56.0.66.0.76.0.86.1.06.1.16.1.26.1.36.1.46.1.5+ 4 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2020-29493CRITICAL10.0PL ✓same product

SQL Injection w Dell EMC Avamar Server — nieautoryzowany dostęp do danych

CVE-2020-29495CRITICAL10.0PL ✓same product

RCE bez uwierzytelnienia w Dell EMC Avamar Server — command injection

CVE-2018-1217CRITICAL9.8PL ✓same product

Brak kontroli dostępu w Dell EMC Avamar Installation Manager — ujawnienie danych uwierzytelniających

CVE-2017-4914CRITICAL9.8PL ✓same product

Zdalne wykonanie kodu przez błąd deserializacji w VMware vSphere Data Protection

CVE-2017-4917CRITICAL9.8PL ✓same product

VMware vSphere Data Protection — odwracalne szyfrowanie danych uwierzytelniających vCenter