CVE-2018-11077
moderate-risk
Published 2018-11-26
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.
Do I need to act?
-
0.37% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.7/10
Medium
LOCAL
/ LOW complexity
Affected Products (20)
References (8)
Third Party Advisory
http://www.securityfocus.com/bid/105971
Third Party Advisory
http://www.securitytracker.com/id/1042153
Mailing List
https://seclists.org/fulldisclosure/2018/Nov/51
Third Party Advisory
http://www.securityfocus.com/bid/105971
Third Party Advisory
http://www.securitytracker.com/id/1042153
Mailing List
https://seclists.org/fulldisclosure/2018/Nov/51
45
/ 100
moderate-risk
Severity
21/34 · High
Exploitability
1/34 · Minimal
Exposure
23/34 · High