PT-2017-2437 · Emc · Emc Avamar Server
Published
2017-06-21
·
Updated
2017-07-07
·
CVE-2017-4990
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EMC Avamar Server Software versions 7.3.0-226 through 7.4.1-58
Description
The issue is related to the lack of restrictions on uploading dangerous file types in the system maintenance page of the EMC Avamar Server Software. This could allow an unauthorized attacker to load a maliciously crafted file to any directory, potentially enabling the execution of arbitrary code on the Avamar Server system. The vulnerability can be exploited by a remote attacker using a specially crafted file.
Recommendations
For versions 7.3.0-226 through 7.4.1-58, consider restricting access to the file upload feature in the system maintenance page until a fix is available. As a temporary workaround, limit the ability to upload files to authorized personnel only, and ensure that all uploaded files are thoroughly scanned for malicious content.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Avamar Server