CVE-2016-0904
EMC Avamar Data Store / Virtual Edition Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
Avamar Data Store (ADS) y Avamar Virtual Edition (AVE) en EMC Avamar Server en versiones anteriores a 7.3.0-233 utilizan la misma clave de cifrado a través de instalaciones de clientes diferentes, lo que permite a atacantes remotos vencer mecanismos de protección criptográfico y obtener información sensible del tráfico cliente-servidor aprovechando el conocimiento de esta clave para otra instalación.
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 7.3 contain fixes for multiple vulnerabilities. These vulnerabilities may expose the Avamar clients and servers to potentially be compromised by malicious users. They include improper authentication, improper encryption, privilege escalation, and command injection vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-17 CVE Reserved
- 2016-09-19 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-310: Cryptographic Issues
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/bugtraq/2016/Sep/31 | Mailing List |
|
http://www.securityfocus.com/bid/93026 | Vdb Entry | |
http://www.securitytracker.com/id/1036844 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Avamar Server Search vendor "Emc" for product "Avamar Server" | <= 7.3.0 Search vendor "Emc" for product "Avamar Server" and version " <= 7.3.0" | - |
Affected
|