Client-side authentication vulnerability in EMC Avamar Server before 7.3.0-233 allows remote attackers to spoof clients and read backup data.

Client-side authentication vulnerability in EMC Avamar Server before 7.3.0-233 allows remote attackers to spoof clients and read backup data.

CVE-2016-0903 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:P/A:N

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.

Learn more about our Cis Benchmark Audit For Server Software.