First published: Wed Sep 21 2016(Updated: )
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Avamar Server Virtual Edition | <=7.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0920 is rated as a critical vulnerability due to its potential for local users to gain root access.
To fix CVE-2016-0920, upgrade your EMC Avamar Server or Avamar Virtual Edition to version 7.3.0-233 or later.
CVE-2016-0920 affects EMC Avamar Server and Avamar Virtual Edition versions prior to 7.3.0-233.
Yes, local users can exploit CVE-2016-0920 to gain unauthorized root access.
Exploitation of CVE-2016-0920 can lead to complete system compromise, allowing malicious users to perform administrative functions.