peter bassill · operator
$ cve CVE-2020-5341 JSON

CVE-2020-5341

9.8
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Deserialization of Untrusted Data Vulnerability Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2, 19.1 and 19.2 and Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 and 2.4.1 contain a Deserialization of Untrusted Data Vulnerability. A remote unauthenticated attacker could exploit this vulnerability to send a serialized payload that would execute code on the system.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.25% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2021-07-28
Last modified2026-06-17

Affected (2)

VendorProduct
dellemc avamar server
dellemc integrated data protection appliance firmware

References

→ the Explorer  ·  watch your stack  ·  NVD