Loading
In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an attacker to view sensitive information, perform software updates, or run maintenance workflows.
Use CWE-287, Emc vendor hub and Avamar Server product page to widen CVE-2017-4989 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-15548, CVE-2017-4990 and CVE-2016-0903 for nearby disclosures in the same product family.