An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avamar_server | Emc | 7.1-21-sp2 (including) | 7.1-21-sp2 (including) |
Avamar_server | Emc | 7.1-145-sp1 (including) | 7.1-145-sp1 (including) |
Avamar_server | Emc | 7.1-302 (including) | 7.1-302 (including) |
Avamar_server | Emc | 7.1-370 (including) | 7.1-370 (including) |
Avamar_server | Emc | 7.2-32-sp1 (including) | 7.2-32-sp1 (including) |
Avamar_server | Emc | 7.2-309 (including) | 7.2-309 (including) |
Avamar_server | Emc | 7.2-401 (including) | 7.2-401 (including) |
Avamar_server | Emc | 7.3-125-sp1 (including) | 7.3-125-sp1 (including) |
Avamar_server | Emc | 7.3-211 (including) | 7.3-211 (including) |
Avamar_server | Emc | 7.3-226 (including) | 7.3-226 (including) |
Avamar_server | Emc | 7.3-233 (including) | 7.3-233 (including) |
Avamar_server | Emc | 7.4-58-sp1 (including) | 7.4-58-sp1 (including) |
Avamar_server | Emc | 7.4-242 (including) | 7.4-242 (including) |
Avamar_server | Emc | 7.5-183 (including) | 7.5-183 (including) |
Integrated_data_protection_appliance | Emc | 2.0 (including) | 2.0 (including) |
Networker | Emc | 9.0 (including) | 9.0 (including) |
Networker | Emc | 9.1 (including) | 9.1 (including) |
Networker | Emc | 9.2 (including) | 9.2 (including) |