Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
EMC Avamar Client before 6.1.101-89 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EMC Avamar 多个SSL凭证安全绕过漏洞
Vulnerability Description
EMC Avamar是美国易安信(EMC)公司的数据去重备份和恢复的解决方案。EMC Avamar Client是其中的客户端软件。 EMC Avamar Client 6.1.101-87及之前的版本中存在漏洞,该漏洞源于程序未正确验证在X.509证书的主题的Common Name (CN)或subjectAltName字段中服务器主机名与域名的匹配。中间人攻击者可通过任意有效的证书利用该漏洞欺骗SSL服务器。
CVSS Information
N/A
Vulnerability Type
N/A