← Back

CVE-2017-15549

nvd nist
Published: Jan 5, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any location on the server file system.

Affected (18)

3 products
Avamar Server
Networker
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Emc
Version 7.1-145 sp1
Version 7.1-21 sp2
Version 7.1-302
Version 7.1-370
Version 7.2-309
Version 7.2-32 sp1
Version 7.2-401
Version 7.3-125 sp1
Version 7.3-211
Version 7.3-226
Version 7.3-233
Version 7.4-242
Version 7.4-58 sp1
Version 7.5-183
Version 2.0
Emc
Version 9.0
Version 9.1
Version 9.2

References (6)

Source: security_alert@emc.com
Issue TrackingMailing ListThird Party Advisory
Source: security_alert@emc.com
Third Party AdvisoryVDB Entry
Source: security_alert@emc.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.