CVE-2013-3275
Summary
| CVE | CVE-2013-3275 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-19 14:36:13 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly restrict use of FRAME elements, which makes it easier for remote attackers to obtain sensitive information via a crafted web site, related to "cross frame scripting vulnerabilities." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Avamar Server | 4.0 | All | All | All |
| Application | Emc | Avamar Server | 4.1 | All | All | All |
| Application | Emc | Avamar Server | 5.0 | All | All | All |
| Application | Emc | Avamar Server | 6.0 | All | All | All |
| Application | Emc | Avamar Server | All | All | All | All |
| Application | Emc | Avamar Server Virtual Edition | 4.0 | All | All | All |
| Application | Emc | Avamar Server Virtual Edition | 4.1 | All | All | All |
| Application | Emc | Avamar Server Virtual Edition | 5.0 | All | All | All |
| Application | Emc | Avamar Server Virtual Edition | 6.0 | All | All | All |
| Application | Emc | Avamar Server Virtual Edition | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| archives.neohapsis.com/archives/bugtraq/2013-07/0114.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.