← Vulnerability feed

Vulnerability record · CVE-2017-15549 · published 5 January 2018

CVE-2017-15549: Emc avamar server unrestricted file upload vulnerability

Emc · Avamar Server

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any location on the server file system.

8.8 CVSS 3.0 High EPSS 5.5% · top 7.5% CWE-434 · Unrestricted file upload
8.8CVSS 3.0 base score, v2 9.0
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any location on the server file system.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2018/Jan/17 Issue TrackingMailing ListThird Party Advisory
http://www.securityfocus.com/bid/102363 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040070 Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2018/Jan/17 Issue TrackingMailing ListThird Party Advisory
http://www.securityfocus.com/bid/102363 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040070 Third Party AdvisoryVDB Entry

Track CVE-2017-15549 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-3892Emc networker vulnerabilityThe Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote …EPSS 4.5%9.8CVE-2017-15548Emc avamar server improper authentication vulnerabilityAn issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Inte…EPSS 4.7%9.8CVE-2017-4989Emc avamar server improper authentication vulnerabilityIn EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypa…EPSS 3.3%9.8CVE-2017-4990Emc avamar server unrestricted file upload vulnerabilityIn EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of …EPSS 3.0%9.8CVE-2016-0916Emc networker improper authentication vulnerabilityEMC NetWorker 8.2.1.x and 8.2.2.x before 8.2.2.6 and 9.x before 9.0.0.6 mishandles authentication, which allows remote attackers to execute arbitrary…EPSS 7.7%9.3CVE-2012-4607Emc networker memory buffer overflow vulnerabilityBuffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code…EPSS 3.2%9.3CVE-2012-2288Emc networker vulnerabilityFormat string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers …EPSS 33%9.3CVE-2012-0395Emc networker memory buffer overflow vulnerabilityBuffer overflow in the server in EMC NetWorker 7.5.x and 7.6.x before 7.6.3 SP1 Cumulative Release build 851 allows remote attackers to cause a denia…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2017-15549), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.