Description
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-0915 | Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation. |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-05T22:38:41.258Z
Reserved: 2015-12-17T00:00:00.000Z
Link: CVE-2016-0904
No data.
Status : Modified
Published: 2016-09-21T02:59:03.053
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-0904
No data.
OpenCVE Enrichment
No data.
EUVD