Avamar Server

Vendor:

First CVE: Jul 19, 2013 · Active for 13 years

13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Avamar Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2013
13 years ago
Most Recent CVE
Jan 5, 2018
3,122 days ago

CVE Severity & Scoring

Avamar Server13 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local3 (23.1%)
Network7 (53.8%)
Unknown3 (23.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (76.9%)
High0 (0.0%)
Unknown3 (23.1%)
User Interaction
None9 (69.2%)
Unknown3 (23.1%)
Required1 (7.7%)
Privileges Required
Low3 (23.1%)
High2 (15.4%)
None5 (38.5%)
Unknown3 (23.1%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Applianc
Jan 5, 20189.832NONO
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Applianc
Jan 5, 20188.831NONO
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to
Jun 21, 20179.831NONO
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Applianc
Jan 5, 20188.830NONO
In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process t
Jun 21, 20179.825NONO
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients an
Sep 21, 20169.123NONO
EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for calls to Java RMI methods, which a
Jul 19, 20139.023NONO
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows r
Sep 21, 20168.622NONO
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is
Sep 21, 20167.820NONO
Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to read arbitrary files by using
Jul 23, 20157.820NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Avamar Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.5-18339.16.2%00
7.4-5839.16.2%00
7.4-24239.16.2%00
7.4.1-5819.83.0%00
7.4.0-24219.83.0%00
7.3-23339.16.2%00
7.3-22639.16.2%00
7.3-21139.16.2%00
7.3-12539.16.2%00
7.3.1-12529.83.2%00
7.3.0-23329.83.2%00
7.3.0-22629.83.2%00
7.2-40139.16.2%00
7.2-3239.16.2%00
7.2-30939.16.2%00
7.2.1-3219.83.3%00
7.2.1-3119.83.3%00
7.2.0-40119.83.3%00
7.1-37039.16.2%00
7.1-30239.16.2%00