VYPR
Critical severity9.8NVD Advisory· Published Jun 21, 2017· Updated May 13, 2026

CVE-2017-4990

CVE-2017-4990

Description

In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.

Affected products

5
  • cpe:2.3:a:emc:avamar_server:7.3.0-226:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:emc:avamar_server:7.3.0-226:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:avamar_server:7.3.0-233:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:avamar_server:7.3.1-125:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:avamar_server:7.4.0-242:*:*:*:*:*:*:*
    • cpe:2.3:a:emc:avamar_server:7.4.1-58:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.