← Vulnerability feed

Vulnerability record · CVE-2017-15548 · published 5 January 2018

CVE-2017-15548: Emc avamar server improper authentication vulnerability

Emc · Avamar Server

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.

9.8 CVSS 3.0 Critical EPSS 4.7% · top 8.5% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 10.0
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2018/Jan/17 Issue TrackingMailing ListThird Party Advisory
http://www.securityfocus.com/bid/102352 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040070 Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2018/Jan/17 Issue TrackingMailing ListThird Party Advisory
http://www.securityfocus.com/bid/102352 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040070 Third Party AdvisoryVDB Entry

Track CVE-2017-15548 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-3892Emc networker vulnerabilityThe Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote …EPSS 4.5%9.8CVE-2017-4989Emc avamar server improper authentication vulnerabilityIn EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypa…EPSS 3.3%9.8CVE-2017-4990Emc avamar server unrestricted file upload vulnerabilityIn EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of …EPSS 3.0%9.8CVE-2016-0916Emc networker improper authentication vulnerabilityEMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary…EPSS 7.7%9.3CVE-2012-4607Emc networker memory buffer overflow vulnerabilityBuffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code…EPSS 3.2%9.3CVE-2012-2288Emc networker vulnerabilityFormat string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers …EPSS 33%9.3CVE-2012-0395Emc networker memory buffer overflow vulnerabilityBuffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denia…EPSS 3.0%9.1CVE-2016-0903Emc avamar server information exposure vulnerabilityAvamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remot…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2017-15548), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.