CVE-2016-0920: Command Injection
Published Sep 21, 2016
·Updated
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.
Affected Software
1 affected component
EMC Avamar Server<=7.3.0
Event History
Sep 21, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0920?
CVE-2016-0920 is rated as a critical vulnerability due to its potential for local users to gain root access.
2
How do I fix CVE-2016-0920?
To fix CVE-2016-0920, upgrade your EMC Avamar Server or Avamar Virtual Edition to version 7.3.0-233 or later.
3
What systems are affected by CVE-2016-0920?
CVE-2016-0920 affects EMC Avamar Server and Avamar Virtual Edition versions prior to 7.3.0-233.
4
Can local users exploit CVE-2016-0920?
Yes, local users can exploit CVE-2016-0920 to gain unauthorized root access.
5
What are the consequences of CVE-2016-0920 exploitation?
Exploitation of CVE-2016-0920 can lead to complete system compromise, allowing malicious users to perform administrative functions.