9.8

CVE-2017-4990

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Avamar Server Version 7.3.0-226
Emc ≫ Avamar Server Version 7.3.0-233
Emc ≫ Avamar Server Version 7.3.1-125
Emc ≫ Avamar Server Version 7.4.0-242
Emc ≫ Avamar Server Version 7.4.1-58
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.03% 0.858
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://www.securityfocus.com/archive/1/540754/30/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/99243
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038718