CVE-2016-0904

Loading...

General

Score:5.0/10.0
Severity:Medium
Category:Cryptography Error

Impact Metrics

Confidentiality:Partial
Integrity:None
Availability:None

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Published on 21/09/16 - Updated on 30/07/17

Description

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.

Category: Cryptography Error

CWE-310 (Cryptographic Issues)
Weaknesses in this category are related to the use of cryptography.

Security Notices

US National Vulnerability DatabaseCVE-2016-0904

Exploits

No exploits available for this CVE in our database.

Relative technologies

VendorProduct
emcavamar_server

Share this vulnerability with:

Twitter Facebook LinkedIn Mail