Back

CVE-2018-11066

CRITICAL

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain a Remote Code Execution vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to execute arbitrary commands on the server.

Published: Nov 26, 2018 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (31)

Vendor Product Version
dell emc_avamar 7.2.0
dell emc_avamar 7.2.1
dell emc_avamar 7.3.0
dell emc_avamar 7.3.1
dell emc_avamar 7.4.0
dell emc_avamar 7.4.1
dell emc_avamar 7.5.0
dell emc_avamar 7.5.1
dell emc_avamar 18.1
dell emc_integrated_data_protection_appliance 2.0
dell emc_integrated_data_protection_appliance 2.1
dell emc_integrated_data_protection_appliance 2.2
vmware vsphere_data_protection 6.0.0
vmware vsphere_data_protection 6.0.1
vmware vsphere_data_protection 6.0.2
vmware vsphere_data_protection 6.0.3
vmware vsphere_data_protection 6.0.4
vmware vsphere_data_protection 6.0.5
vmware vsphere_data_protection 6.0.6
vmware vsphere_data_protection 6.0.7

…and 11 more

GitHub Security Advisory GHSA-m593-g9cm-c9fm

Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 9.91%

Top 5% most likely to be exploited

Threat Score 42.2 / 100

Data Sources

NVD EPSS GitHub