First published: Wed Sep 21 2016(Updated: )
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Avamar Server Virtual Edition | <=7.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0904 has been classified with a medium severity rating due to the potential exposure of sensitive client-server traffic.
To mitigate CVE-2016-0904, it is recommended to upgrade to EMC Avamar Server version 7.3.0-233 or later.
CVE-2016-0904 allows remote attackers to access sensitive information by exploiting the use of the same encryption key across different installations.
CVE-2016-0904 affects all versions of EMC Avamar Server prior to 7.3.0-233.
Yes, CVE-2016-0904 can be exploited remotely, allowing attackers to defeat cryptographic protections.