OS Command Injection Vulnerability in DELL EMC Avamar Server
CVE-2020-29495

10CRITICAL

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
14 January 2021

Summary

The DELL EMC Avamar Server, specifically versions 19.1, 19.2, and 19.3, is affected by an OS Command Injection vulnerability found in Fitness Analyzer. This flaw allows a remote, unauthenticated attacker to execute arbitrary operating system commands with high privileges. Due to the nature of this vulnerability, an attacker could potentially take full control of the affected application and its underlying operating system. DELL advises immediate upgrading to mitigate the risk associated with this vulnerability.

Affected Version(s)

Avamar < unspecified

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.