CVE-2016-0905: High severity emc avamar server virtual edition vulnerability
Published Sep 21, 2016
·Updated
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command.
Affected Software
1 affected component
EMC Avamar Server<=7.3.0
Event History
Sep 21, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0905?
CVE-2016-0905 has a high severity level due to the potential for local users to gain root privileges.
2
How do I fix CVE-2016-0905?
To fix CVE-2016-0905, upgrade EMC Avamar Server to version 7.3.0-234 or later.
3
Who is affected by CVE-2016-0905?
CVE-2016-0905 affects users of EMC Avamar Data Store and Avamar Virtual Edition before version 7.3.0-233.
4
What kind of access is required to exploit CVE-2016-0905?
Exploitation of CVE-2016-0905 requires local access as an admin user to execute the sudo command.
5
What is the impact of CVE-2016-0905?
The impact of CVE-2016-0905 includes unauthorized escalation of privileges to root, compromising the security of the system.