CVE-2017-4989: Critical severity emc avamar server virtual edition vulnerability
In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an attacker to view sensitive information, perform software updates, or run maintenance workflows.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4989?
CVE-2017-4989 has been classified as having a high severity due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2017-4989?
To remediate CVE-2017-4989, update your EMC Avamar Server Software to the latest patched version provided by Dell EMC.
Which versions of EMC Avamar Server Software are affected by CVE-2017-4989?
CVE-2017-4989 affects EMC Avamar Server Software versions 7.2.0-401, 7.2.1-31, 7.2.1-32, 7.3.0-226, 7.3.0-233, and 7.3.1-125.
What is the impact of CVE-2017-4989?
The impact of CVE-2017-4989 allows unauthenticated remote attackers to bypass authentication and gain access to sensitive maintenance pages.
Is there a workaround for CVE-2017-4989?
While upgrading is the recommended approach, temporary access controls or network segmentation may serve as a workaround for CVE-2017-4989.