CVE-2016-0904: Infoleak
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0904?
CVE-2016-0904 has been classified with a medium severity rating due to the potential exposure of sensitive client-server traffic.
How do I fix CVE-2016-0904?
To mitigate CVE-2016-0904, it is recommended to upgrade to EMC Avamar Server version 7.3.0-233 or later.
What impact does CVE-2016-0904 have on affected systems?
CVE-2016-0904 allows remote attackers to access sensitive information by exploiting the use of the same encryption key across different installations.
Which versions of Avamar are affected by CVE-2016-0904?
CVE-2016-0904 affects all versions of EMC Avamar Server prior to 7.3.0-233.
Can CVE-2016-0904 be exploited remotely?
Yes, CVE-2016-0904 can be exploited remotely, allowing attackers to defeat cryptographic protections.