HIGH · 9.0

CVE-2007-1836

The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in certain arguments to various comm...

Vulnerability Description

The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in certain arguments to various commands, as demonstrated by the interface argument to the (1) ifconfig and (2) ping commands.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Data DomainData Domain Os<= 4.0.3.5

References

FAQ

What is CVE-2007-1836?

CVE-2007-1836 is a vulnerability with a CVSS score of 9.0 (HIGH). The command line administration interface in Data Domain OS before 4.0.3.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in certain arguments to various comm...

How severe is CVE-2007-1836?

CVE-2007-1836 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1836?

Check the references section above for vendor advisories and patch information. Affected products include: Data Domain Data Domain Os.