CVE-2018-11077

'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
VendorProductVersion
dellemc_avamar
7.2.0
dellemc_avamar
7.2.1
dellemc_avamar
7.3.0
dellemc_avamar
7.3.1
dellemc_avamar
7.4.0
dellemc_avamar
7.4.1
dellemc_avamar
7.5.0
dellemc_avamar
7.5.1
dellemc_avamar
18.1
dellemc_integrated_data_protection_appliance
2.0
dellemc_integrated_data_protection_appliance
2.1
dellemc_integrated_data_protection_appliance
2.2
vmwarevsphere_data_protection
6.0.0
vmwarevsphere_data_protection
6.0.1
vmwarevsphere_data_protection
6.0.2
vmwarevsphere_data_protection
6.0.3
vmwarevsphere_data_protection
6.0.4
vmwarevsphere_data_protection
6.0.5
vmwarevsphere_data_protection
6.0.6
vmwarevsphere_data_protection
6.0.7
vmwarevsphere_data_protection
6.0.8
vmwarevsphere_data_protection
6.1.0
vmwarevsphere_data_protection
6.1.1
vmwarevsphere_data_protection
6.1.2
vmwarevsphere_data_protection
6.1.3
vmwarevsphere_data_protection
6.1.4
vmwarevsphere_data_protection
6.1.5
vmwarevsphere_data_protection
6.1.6
vmwarevsphere_data_protection
6.1.7
vmwarevsphere_data_protection
6.1.8
vmwarevsphere_data_protection
6.1.9
𝑥
= Vulnerable software versions