Avamar
Vendor:
First CVE: May 28, 2010 · Active for 16 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Avamar over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 28, 2010
16 years ago
Most Recent CVE
Jul 6, 2016
3,671 days ago
CVE Severity & Scoring
Avamar10 CVEs
30%
10%
60%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (90.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0648HIGH Unspecified vulnerability in EMC Avamar before 5.0.4-30 allows remote authenticated users to gain privileges via unknown vectors. | Mar 16, 2011 | 8.5 | 26 | NO | NO |
CVE-2013-0945HIGH EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificat | May 3, 2013 | 9.3 | 23 | NO | NO |
CVE-2016-0906HIGH The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read | Jul 6, 2016 | 8.8 | 22 | NO | NO |
CVE-2012-2291HIGH EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allo | Jan 21, 2013 | 7.2 | 21 | NO | NO |
CVE-2010-1919HIGH Unspecified vulnerability in EMC Avamar 4.1.x and 5.0 before SP1 allows remote attackers to cause a denial of service (gsan service hang) by sending a crafted message using TCP. | May 28, 2010 | 7.1 | 21 | NO | NO |
CVE-2011-1740HIGH EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about product activities by leveraging pri | Sep 19, 2011 | 7.7 | 20 | NO | NO |
The service utility in EMC Avamar 5.x before 5.0.4 uses cleartext to transmit event details in (1) service requests and (2) e-mail messages, which might allow remote attackers to o | Mar 16, 2011 | 3.5 | 15 | NO | NO |
CVE-2014-4623MEDIUM EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for p | Oct 25, 2014 | 4.3 | 14 | NO | NO |
EMC Avamar Client for VMware 6.1 stores the cleartext server root password on the proxy client, which might allow remote attackers to obtain sensitive information by leveraging "ne | Oct 31, 2012 | 3.3 | 14 | NO | NO |
The web-based file-restore interface in EMC Avamar Server before 6.1.0 allows remote authenticated users to read arbitrary files via a crafted URL. | May 3, 2013 | 3.5 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Avamar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 1 | 4.3 | 1.6% | 0 | 0 |
| 6.1.101-87 | 1 | 4.3 | 1.6% | 0 | 0 |
| 6.1 | 2 | 3.8 | 1.1% | 0 | 0 |
| 6.0.3 | 2 | 3.9 | 1.2% | 0 | 0 |
| 6.0.2 | 2 | 3.9 | 1.2% | 0 | 0 |
| 6.0.1 | 2 | 3.9 | 1.2% | 0 | 0 |
| 6.0 | 4 | 6.9 | 0.8% | 0 | 0 |
| 5.0.4-26 | 4 | 6.9 | 0.8% | 0 | 0 |
| 5.0.0-407 | 4 | 6.9 | 0.8% | 0 | 0 |
| 5.0 | 6 | 6.6 | 0.9% | 0 | 0 |
| 4.1 | 5 | 8.0 | 1.5% | 0 | 0 |
| 4.0 | 3 | 8.1 | 0.8% | 0 | 0 |