9.8

CVE-2017-4989

In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an attacker to view sensitive information, perform software updates, or run maintenance workflows.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Avamar Server Version 7.2.0-401
Emc ≫ Avamar Server Version 7.2.1-31
Emc ≫ Avamar Server Version 7.2.1-32
Emc ≫ Avamar Server Version 7.3.0-226
Emc ≫ Avamar Server Version 7.3.0-233
Emc ≫ Avamar Server Version 7.3.1-125
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.29% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://www.securityfocus.com/archive/1/540754/30/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/99243
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038718