VYPR
Critical severity9.8NVD Advisory· Published Jul 28, 2021· Updated Jun 17, 2026

CVE-2020-5341

CVE-2020-5341

Description

Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 and 2.4.1 contain a Deserialization of Untrusted Data Vulnerability. A remote unauthenticated attacker could exploit this vulnerability to send a serialized payload that would execute code on the system.

Affected products

16
  • cpe:2.3:a:dell:emc_avamar_server:18.1:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:dell:emc_avamar_server:18.1:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_avamar_server:18.2:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_avamar_server:19.1:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_avamar_server:19.2:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_avamar_server:7.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_avamar_server:7.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:dell:emc_avamar_server:7.5.1:*:*:*:*:*:*:*
  • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.0:*:*:*:*:*:*:*
    • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.1:*:*:*:*:*:*:*
    • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.2:*:*:*:*:*:*:*
    • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.3:*:*:*:*:*:*:*
    • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.4.1:*:*:*:*:*:*:*
    • cpe:2.3:o:dell:emc_integrated_data_protection_appliance_firmware:2.4:*:*:*:*:*:*:*
  • Range: 2.0, 2.1, 2.2, 2.3, 2.4, 2.4.1
  • Range: 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1, 19.2
  • Dell/Avamar Virtual Editionv5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.