Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/bugtraq/2016/Sep/31 | mailing list vdb entry third party advisory |
http://www.securityfocus.com/bid/93026 | vdb entry |
http://www.securitytracker.com/id/1036844 | vdb entry |