EMC Avamar ADS / AVE 7.2.x < 7.2.1 Hotfix 277897 / 7.3.x < 7.3.1 Hotfix 276676 / 7.4.x < 7.4.1 Hotfix 279294 Multiple Vulnerabilities (ESA-2017-054)

critical Nessus Plugin ID 101110

Synopsis

A backup solution running on the remote host is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the EMC Avamar Data Store (ADS) or Avamar Virtual Edition (AVE) software running on the remote host is 7.2.x prior to 7.2.1 Hotfix 277897 (7.2.1.32), 7.3.x prior to 7.3.1 Hotfix 276676 (7.3.1.125), or 7.4.x prior to 7.4.1 Hotfix 279294 (7.4.1.58). It is, therefore, affected by multiple vulnerabilities :

- An authentication bypass vulnerability exists that allows an unauthenticated, remote attacker to bypass authentication and gain access to the system maintenance page. Note that this vulnerability does not affect the 7.4.x version branch. (CVE-2017-4989)

- A remote code execution vulnerability exists in the file upload feature of the system maintenance page due to improper validation of file types and extensions of uploaded files before being placed in a user-accessible path. An unauthenticated, remote attacker can exploit this to upload a specially crafted file and then request it in order to execute arbitrary code. Note that this vulnerability does not affect the 7.2.x version branch.
(CVE-2017-4990)

Solution

Upgrade to EMC Avamar ADS / AVE version 7.2.1 Hotfix 277897 (7.2.1.32) / 7.3.1 Hotfix 276676 (7.3.1.125) / 7.4.1 Hotfix 279294 (7.4.1.58) or later.

See Also

https://seclists.org/bugtraq/2017/Jun/att-40/ESA-2017-054.txt

Plugin Details

Severity: Critical

ID: 101110

File Name: emc_avamar_esa-2017-054.nasl

Version: 1.6

Type: combined

Family: Misc.

Published: 6/29/2017

Updated: 11/12/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2017-4990

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:emc:avamar_data_store, cpe:/a:emc:avamar, cpe:/a:emc:avamar_server_virtual_edition

Required KB Items: installed_sw/EMC Avamar

Exploit Ease: No known exploits are available

Patch Publication Date: 6/20/2017

Vulnerability Publication Date: 6/20/2017

Reference Information

CVE: CVE-2017-4989, CVE-2017-4990

BID: 99243

IAVB: 2017-B-0076