Vulnerability Details CVE-2017-4990
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 83.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2017-4990
-
cpe:2.3:a:emc:avamar_server:7.3.0-226
-
cpe:2.3:a:emc:avamar_server:7.3.0-233
-
cpe:2.3:a:emc:avamar_server:7.3.1-125
-
cpe:2.3:a:emc:avamar_server:7.4.0-242
-
cpe:2.3:a:emc:avamar_server:7.4.1-58