PT-2017-2438 · Emc · Emc Avamar Server
Published
2017-06-21
·
Updated
2017-07-07
·
CVE-2017-4989
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EMC Avamar Server Software versions 7.2.0-401 through 7.3.1-125
Description
The issue is related to weaknesses in the authentication procedure of the EMC Avamar backup system. It may allow a remote attacker to bypass authentication, gaining access to sensitive information, performing software updates, or executing other maintenance operations.
Recommendations
For versions 7.2.0-401 through 7.3.1-125, consider restricting access to the system maintenance page as a temporary workaround until a patch is available. Additionally, review and strengthen the authentication process to prevent unauthorized access.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Avamar Server