PT-2018-1031 · Emc · Emc Avamar Server+2

Michael Cramer

·

Published

2018-01-03

·

Updated

2018-01-18

·

CVE-2017-15548

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EMC Avamar Server versions 7.1.x through 7.5.0 EMC NetWorker Virtual Edition (NVE) versions 9.0.x through 9.2.x EMC Integrated Data Protection Appliance version 2.0
Description The issue is related to weaknesses in the authentication procedure of the affected systems. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the systems. The vulnerability can be exploited by a remote attacker to bypass authentication and obtain root access.
Recommendations For EMC Avamar Server versions 7.1.x through 7.5.0, update to a version that addresses the authentication bypass issue. For EMC NetWorker Virtual Edition (NVE) versions 9.0.x through 9.2.x, update to a version that addresses the authentication bypass issue. For EMC Integrated Data Protection Appliance version 2.0, update to a version that addresses the authentication bypass issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00329
CVE-2017-15548

Affected Products

Emc Avamar Server
Emc Integrated Data Protection Appliance
Emc Networker Virtual Edition