CVE-2016-0921: Emc Avamar Server

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with a Trojan horse program.

Affected products

  • Emc Avamar Server: up to and including 7.3.0

Published 2016-09-21. Last modified 2026-06-17.