CVE-2017-4989: Emc Avamar Server
Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.
In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an attacker to view sensitive information, perform software updates, or run maintenance workflows.
Affected products
- Emc Avamar Server: version 7.2.0-401 only; version 7.2.1-31 only; version 7.2.1-32 only; version 7.3.0-226 only; version 7.3.0-233 only; version 7.3.1-125 only
Published 2017-06-21. Last modified 2026-06-17.