Medium severity6.7NVD Advisory· Published Nov 26, 2018· Updated Jun 17, 2026
CVE-2018-11077
CVE-2018-11077
Description
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection vulnerability. A malicious Avamar admin user may potentially be able to execute arbitrary commands under root privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
35cpe:2.3:a:dell:emc_avamar:18.1:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:dell:emc_avamar:18.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_avamar:7.5.1:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vsphere_data_protection:6.0.0:*:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vsphere_data_protection:6.1.9:*:*:*:*:*:*:*
- Range: 2.0, 2.1 and 2.2
- Range: 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1
- Range: 7.2.0
- Range: 2.0
Patches
Vulnerability mechanics
References
4- www.vmware.com/security/advisories/VMSA-2018-0029.htmlnvdPatchThird Party Advisory
- www.securityfocus.com/bid/105971nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1042153nvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2018/Nov/51nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.