3.5

CVE-2013-0944

The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL.

Data is provided by the National Vulnerability Database (NVD)
EmcAvamar Version5.0
EmcAvamar Version5.0 Updatesp1
EmcAvamar Version5.0 Updatesp2
EmcAvamar Version5.0.0-407
EmcAvamar Version5.0.4-26
EmcAvamar Version6.0
EmcAvamar Version6.0.1
EmcAvamar Version6.0.2
EmcAvamar Version6.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.16% 0.337
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.