Vulnerability Description
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Emc | Avamar Server | 7.3.0-226 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/540754/30/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/99243Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038718
- http://www.securityfocus.com/archive/1/540754/30/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/99243Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038718
FAQ
What is CVE-2017-4990?
CVE-2017-4990 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously c...
How severe is CVE-2017-4990?
CVE-2017-4990 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-4990?
Check the references section above for vendor advisories and patch information. Affected products include: Emc Avamar Server.