Critical severity9.8NVD Advisory· Published Jun 21, 2017· Updated May 13, 2026
CVE-2017-4990
CVE-2017-4990
Description
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
Affected products
5cpe:2.3:a:emc:avamar_server:7.3.0-226:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:emc:avamar_server:7.3.0-226:*:*:*:*:*:*:*
- cpe:2.3:a:emc:avamar_server:7.3.0-233:*:*:*:*:*:*:*
- cpe:2.3:a:emc:avamar_server:7.3.1-125:*:*:*:*:*:*:*
- cpe:2.3:a:emc:avamar_server:7.4.0-242:*:*:*:*:*:*:*
- cpe:2.3:a:emc:avamar_server:7.4.1-58:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/archive/1/540754/30/0/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/99243nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1038718nvd
News mentions
0No linked articles in our index yet.