CVE-2014-4623: Medium severity emc avamar virtual edition vulnerability
EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4623?
CVE-2014-4623 has a medium severity due to its potential to allow brute-force password cracking.
How do I fix CVE-2014-4623?
To fix CVE-2014-4623, upgrade to an Avamar version where Password Hardening is implemented using stronger hashing algorithms.
Which versions are affected by CVE-2014-4623?
CVE-2014-4623 affects EMC Avamar versions 6.0.x, 6.1.x, and 7.0.x prior to the patch that includes enhanced password hashing.
What type of attacks does CVE-2014-4623 make easier?
CVE-2014-4623 makes it easier for attackers to execute brute-force attacks to obtain cleartext passwords.
Is CVE-2014-4623 specific to a particular environment?
CVE-2014-4623 specifically affects EMC Avamar Data Store deployments with Password Hardening enabled before version 2.0.0.4.