CVE-2016-0904

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:emc:avamar_server:*:*:*:*:*:*:*:*

Information

Published : 2016-09-20 19:59

Updated : 2017-07-29 18:29


NVD link : CVE-2016-0904

Mitre link : CVE-2016-0904


JSON object : View

CWE
CWE-310

Cryptographic Issues

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

emc

  • avamar_server