CVE-2018-11066
9.8
CRITICAL · CVSS 3.0 · EPSS 9.9% (pctl 95)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary commands on the server.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.91% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-11-26 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| dell | emc avamar |
| dell | emc integrated data protection appliance |
| vmware | vsphere data protection |
References
- http://www.securityfocus.com/bid/105968
- http://www.securitytracker.com/id/1042153
- https://seclists.org/fulldisclosure/2018/Nov/49
- https://www.vmware.com/security/advisories/VMSA-2018-0029.html
- http://www.securityfocus.com/bid/105968
- http://www.securitytracker.com/id/1042153
- https://seclists.org/fulldisclosure/2018/Nov/49
- https://www.vmware.com/security/advisories/VMSA-2018-0029.html
→ the Explorer · watch your stack · NVD