CVE-2016-0903
9.1
CRITICAL · CVSS 3.0 · EPSS 3.4% (pctl 89)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 3.45% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-09-21 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| emc | avamar server |
References
→ the Explorer · watch your stack · NVD