PT-2021-11677 · Dell · Dell Emc Avamar Server
Published
2021-01-14
·
Updated
2021-01-21
·
CVE-2020-29495
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DELL EMC Avamar Server versions 19.1 through 19.3
Description:
The issue is an OS Command Injection Vulnerability in the Fitness Analyzer component. A remote unauthenticated attacker could potentially exploit this, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This can be leveraged to completely compromise the vulnerable application as well as the underlying operating system.
Recommendations:
For versions 19.1 through 19.3, upgrade to a newer version at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting access to the Fitness Analyzer component until a patch is available.
Fix
OS Command Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Emc Avamar Server