CVE-2017-4990: Emc Avamar Server
Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the attacker to execute arbitrary code on the Avamar Server system.
Affected products
- Emc Avamar Server: version 7.3.0-226 only; version 7.3.0-233 only; version 7.3.1-125 only; version 7.4.0-242 only; version 7.4.1-58 only
Published 2017-06-21. Last modified 2026-06-17.