![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.106289 |
Categoría: | Web application abuses |
Título: | EMC Avamar < 7.3.0-233 Multiple Vulnerabilities |
Resumen: | EMC Avamar is prone to multiple vulnerabilities. |
Descripción: | Summary: EMC Avamar is prone to multiple vulnerabilities. Vulnerability Insight: The following vulnerabilities exist: - CVE-2016-0903: Improper client side authentication - CVE-2016-0904: Improper encryption of communication channel - CVE-2016-0905: Privilege escalation via sudo - CVE-2016-0920: Command Injection in sudo script - CVE-2016-0921: Privilege escalation due to weak file permissions Vulnerability Impact: An attacker may obtain root privileges, obtain sensitive client-server traffic information or read backup data. Affected Software/OS: EMC Avamar prior to version 7.3.0. Solution: Update to version 7.3.0-233 or later. CVSS Score: 7.2 CVSS Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-0903 BugTraq ID: 93026 http://www.securityfocus.com/bid/93026 Bugtraq: 20160919 ESA-2016-065: EMC Avamar Data Store and Avamar Virtual Edition Multiple Vulnerabilities (Google Search) http://seclists.org/bugtraq/2016/Sep/31 http://www.securitytracker.com/id/1036844 Common Vulnerability Exposure (CVE) ID: CVE-2016-0904 Common Vulnerability Exposure (CVE) ID: CVE-2016-0905 BugTraq ID: 93032 http://www.securityfocus.com/bid/93032 Common Vulnerability Exposure (CVE) ID: CVE-2016-0920 Common Vulnerability Exposure (CVE) ID: CVE-2016-0921 |
Copyright | Copyright (C) 2016 Greenbone AG |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |