Vulnerability Intelligence Report
CVE-2013-0945
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:0.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| emc | avamar | 4.0, 4.1, 5.0, 5.0.0-407, 5.0.4-26, 6.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.858%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dell · Vendor · USA |
| Reserved | 2013-01-09T00:00:00 |
| Published | 2013-05-03T10:00:00 |
| Last Updated | 2024-09-17T00:50:49 |
Community Chatter & Buzz