CVE-2013-0945: Input Validation
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0945?
CVE-2013-0945 is classified as a medium severity vulnerability due to potential man-in-the-middle attacks.
How do I fix CVE-2013-0945?
To fix CVE-2013-0945, upgrade to a version of the EMC Avamar Client that is 6.1.101-89 or later.
What software versions are affected by CVE-2013-0945?
CVE-2013-0945 affects EMC Avamar versions before 6.1.101-89, including versions 4.0, 4.1, 5.0, and 6.0.
What kind of attacks does CVE-2013-0945 allow?
CVE-2013-0945 allows man-in-the-middle attackers to spoof SSL servers using an arbitrary valid certificate.
Why is CVE-2013-0945 a concern for security?
CVE-2013-0945 is a concern because it undermines SSL security mechanisms by not properly verifying the server's hostname.