First published: Wed Sep 21 2016(Updated: )
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with a Trojan horse program.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Avamar Server Virtual Edition | <=7.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0921 has a medium severity rating due to weak permissions that can allow local users to gain root access.
To fix CVE-2016-0921, update your EMC Avamar Server to version 7.3.0-234 or later to ensure proper permissions are enforced.
CVE-2016-0921 affects EMC Avamar Server versions prior to 7.3.0-233, including Avamar Data Store (ADS) and Avamar Virtual Edition (AVE).
CVE-2016-0921 allows local users to obtain root access by replacing vulnerable scripts with malicious programs.
CVE-2016-0921 is a vulnerability that stems from weak permissions, which can be exploited by local users.