Vulnerability Intelligence Report
CVE-2020-29495
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This vulnerability is considered critical as it can be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:6.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Dell | Avamar | unspecified < HF 19.1, 19.2, 19.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
6.158%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dell · Vendor · USA |
| Reserved | 2020-12-03T00:00:00 |
| Published | 2021-01-14T21:10:16 |
| Patch Date | 2020-01-21 |
| Last Updated | 2024-09-16T16:12:48 |
Community Chatter & Buzz