Avamar: How to address Security Vulnerabilities or a Common Vulnerabilities and Exposures (CVE) on Avamar systems

Summary: This article shows how customers can address a security vulnerability on their Avamar system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

This article is for customers who have noticed a security vulnerability or a Common Vulnerabilities and Exposures (CVE) or have received a report from an automated scanning tool.
  1. Check if the vulnerabilities are addressed in Avamar Security Rollup Release Notes
  2. Check if the latest Avamar Security Rollup (AvPlatformOSRollup) is installed. 
  3. If the vulnerabilities are already addressed in the Rollup, Schedule installation with the Avamar Upgrade Team. 
  4. If the vulnerability is not addressed in Avamar Security Rollup, open a service request with the Dell Technologies Avamar Customer Support team to address the vulnerability. 

Note: Do not install any software or patch on the Avamar system that is not provided by Avamar Engineering. 

Additional Information

How to check installed software on the Avamar System.

  • Software in Avamar is provided as and Avamar Package (AVP) and installed using Avamar installation manager (AVI).
  • Log in to AVI using root credentials, https://<servername>/avi  Where <servername> is the hostname or IP address of the Avamar system. 
  • Select the History Tab to check for previously installed hotfixes and patches.
 
kA53a0000004OItCAM_3_0
 

Where to find the latest Avamar Security Rollup (Product Security Rollup)
  • The Security Rollup can be downloaded from the Avamar Support Site. 
  • Select the Update kit and download the Platform Security Rollup.  Always download the latest file.  The example below shows 2020 R4. 
 
Rollup_Download.JPG
Where to find Security Advisories. 
kA53a0000004OItCAM_3_2


 

Scenario 1: If the latest OS security rollup is not installed, it is required to get it installed first by following the below:


1. How to install Security Rollup:

  • Customers with Avamar Hardware (ADS) can reach out to the Avamar scheduling team to install the Security Rollup.
  • Customers using Avamar Virtual Edition can download and install the Rollup themselves. Check KB 169784 for more information.

2. Re-run the security scan once Avamar has the latest AvPlatformOSRollup:

  • Once Avamar has the latest AvPlatformOSRollup installed, The security scanning tool should be updated with the latest release, and then re-run the scan.
  • This is because any scan or manual assessment performed before the latest AvPlatformOSRollup is installed would not provide useful results.
 

Scenario 2: If the vulnerability is not addressed, open a service request with the Avamar Support team to address the vulnerability by providing the below information:
 

  • The name of the scanning tool being used and the version/update level
  • A copy of the scan report
  • All information about the business impact (Note: This is typically based on the severity level of the vulnerability)
  • Provide the names of the systems and the IPs and ports that are affected, according to the scan report.
  • For each vulnerability reported in the scan, provide:

a) A CVE ID (https://nvd.nist.gov/) if not already given in the scan report
b) A web link to the third-party vendor alert, where there is one.


More articles

  • KB 169784 - Installing the latest Avamar Platform Security Rollup on the Avamar Proxy and the NetWorker External Proxy 
 

Affected Products

Avamar, Avamar Server, Avamar Virtual Edition

Products

Avamar
Article Properties
Article Number: 000021586
Article Type: How To
Last Modified: 04 Sep 2024
Version:  6
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.