First published: Wed Sep 21 2016(Updated: )
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Avamar Server Virtual Edition | <=7.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0905 has a high severity level due to the potential for local users to gain root privileges.
To fix CVE-2016-0905, upgrade EMC Avamar Server to version 7.3.0-234 or later.
CVE-2016-0905 affects users of EMC Avamar Data Store and Avamar Virtual Edition before version 7.3.0-233.
Exploitation of CVE-2016-0905 requires local access as an admin user to execute the sudo command.
The impact of CVE-2016-0905 includes unauthorized escalation of privileges to root, compromising the security of the system.