Avamar Server
Vendor:
First CVE: Jul 19, 2013 · Active for 13 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Avamar Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2013
13 years ago
Most Recent CVE
Jan 5, 2018
3,122 days ago
CVE Severity & Scoring
Avamar Server13 CVEs
23%
46%
31%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (23.1%)
Network7 (53.8%)
Unknown3 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High0 (0.0%)
Unknown3 (23.1%)
User Interaction
None9 (69.2%)
Unknown3 (23.1%)
Required1 (7.7%)
Privileges Required
Low3 (23.1%)
High2 (15.4%)
None5 (38.5%)
Unknown3 (23.1%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15548CRITICAL An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Applianc | Jan 5, 2018 | 9.8 | 32 | NO | NO |
CVE-2017-15550HIGH An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Applianc | Jan 5, 2018 | 8.8 | 31 | NO | NO |
CVE-2017-4990CRITICAL In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to | Jun 21, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-15549HIGH An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Applianc | Jan 5, 2018 | 8.8 | 30 | NO | NO |
CVE-2017-4989CRITICAL In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process t | Jun 21, 2017 | 9.8 | 25 | NO | NO |
CVE-2016-0903CRITICAL Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients an | Sep 21, 2016 | 9.1 | 23 | NO | NO |
CVE-2013-3274HIGH EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which a | Jul 19, 2013 | 9.0 | 23 | NO | NO |
CVE-2016-0904HIGH Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows r | Sep 21, 2016 | 8.6 | 22 | NO | NO |
CVE-2016-0920HIGH Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is | Sep 21, 2016 | 7.8 | 20 | NO | NO |
CVE-2015-4527HIGH Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using | Jul 23, 2015 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Avamar Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.5-183 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.4-58 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.4-242 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.4.1-58 | 1 | 9.8 | 3.0% | 0 | 0 |
| 7.4.0-242 | 1 | 9.8 | 3.0% | 0 | 0 |
| 7.3-233 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.3-226 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.3-211 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.3-125 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.3.1-125 | 2 | 9.8 | 3.2% | 0 | 0 |
| 7.3.0-233 | 2 | 9.8 | 3.2% | 0 | 0 |
| 7.3.0-226 | 2 | 9.8 | 3.2% | 0 | 0 |
| 7.2-401 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.2-32 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.2-309 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.2.1-32 | 1 | 9.8 | 3.3% | 0 | 0 |
| 7.2.1-31 | 1 | 9.8 | 3.3% | 0 | 0 |
| 7.2.0-401 | 1 | 9.8 | 3.3% | 0 | 0 |
| 7.1-370 | 3 | 9.1 | 6.2% | 0 | 0 |
| 7.1-302 | 3 | 9.1 | 6.2% | 0 | 0 |