CVE-2016-0921: Medium severity emc avamar server virtual edition vulnerability
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with a Trojan horse program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0921?
CVE-2016-0921 has a medium severity rating due to weak permissions that can allow local users to gain root access.
How can I fix CVE-2016-0921?
To fix CVE-2016-0921, update your EMC Avamar Server to version 7.3.0-234 or later to ensure proper permissions are enforced.
What systems are affected by CVE-2016-0921?
CVE-2016-0921 affects EMC Avamar Server versions prior to 7.3.0-233, including Avamar Data Store (ADS) and Avamar Virtual Edition (AVE).
What kind of access can be obtained through CVE-2016-0921?
CVE-2016-0921 allows local users to obtain root access by replacing vulnerable scripts with malicious programs.
Is CVE-2016-0921 an exploit or a vulnerability?
CVE-2016-0921 is a vulnerability that stems from weak permissions, which can be exploited by local users.