Junglewise Threat Intelligence

CVE-2016-8214: EMC Avamar permission issues in ADS and AVE

CVE-2016-8214 · Severity: medium · CVSS 6.7 · Published 2017-01-25

Executive brief

EMC Avamar Data Store and Virtual Edition, which are used for enterprise data backup and recovery, contain a security vulnerability that could allow an administrator to compromise the underlying server. If exploited, a malicious user with administrative privileges could gain unauthorized control over the backup infrastructure, potentially leading to data loss or service disruption. This issue affects versions 7.3.0 and 7.3.1 of the software.

Technical details

A permission issue (CWE-275) in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3.0 and 7.3.1 allows local users with high privileges to compromise the server. The vulnerability is triggered locally and requires administrative credentials (PR:H). Successful exploitation allows an attacker to gain full control over the confidentiality, integrity, and availability of the affected Avamar server. The issue was disclosed in early 2017 and affects specific 7.3.x release branches.

Affected products

  • EMC Avamar Data Store (ADS) 7.3.0, 7.3.1
  • EMC Avamar Virtual Edition (AVE) 7.3.0, 7.3.1

Timeline

  • 2017-01-25: disclosed: Initial NVD publication date

References