CVE-2017-15548: Critical severity EMC Avamar Server vulnerability
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15548?
CVE-2017-15548 is a vulnerability in EMC Avamar Server, EMC NetWorker Virtual Edition (NVE), and EMC Integrated Data Protection Appliance that allows a remote unauthenticated attacker to bypass authentication and gain unauthorized access.
What is the severity of CVE-2017-15548?
The severity of CVE-2017-15548 is critical with a CVSS score of 9.8 out of 10.
Which versions of EMC Avamar Server are affected by CVE-2017-15548?
EMC Avamar Server versions 7.1.x, 7.2.x, 7.3.x, 7.4.x, and 7.5.0 are all affected by CVE-2017-15548.
Which versions of EMC NetWorker Virtual Edition are affected by CVE-2017-15548?
EMC NetWorker Virtual Edition versions 9.0.x, 9.1.x, and 9.2.x are affected by CVE-2017-15548.
Is there a fix available for CVE-2017-15548?
Yes, EMC has released patches and updates to address the vulnerability in affected products. It is recommended to apply the latest security updates to mitigate the risk.