CVE-2016-0903: Emc Avamar Server
Critical severity, CVSS 9.1. EPSS: 3.4% chance of exploitation in the next 30 days.
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.
Affected products
- Emc Avamar Server: up to and including 7.3.0
Published 2016-09-21. Last modified 2026-06-17.