Avamar: How to address Security Vulnerabilities or a Common Vulnerabilities and Exposures (CVE) on Avamar systems
Summary: This article shows how customers can address a security vulnerability on their Avamar system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Instructions
This article is for customers who have noticed a security vulnerability or a Common Vulnerabilities and Exposures (CVE) or have received a report from an automated scanning tool.
Note: Do not install any software or patch on the Avamar system that is not provided by Avamar Engineering.
- Check if the vulnerabilities are addressed in Avamar Security Rollup Release Notes.
- Check if the latest Avamar Security Rollup (AvPlatformOSRollup) is installed.
- If the vulnerabilities are already addressed in the Rollup, Schedule installation with the Avamar Upgrade Team.
- If the vulnerability is not addressed in Avamar Security Rollup, open a service request with the Dell Technologies Avamar Customer Support team to address the vulnerability.
Note: Do not install any software or patch on the Avamar system that is not provided by Avamar Engineering.
Additional Information
How to check installed software on the Avamar System.
- Software in Avamar is provided as and Avamar Package (AVP) and installed using Avamar installation manager (AVI).
- Log in to AVI using root credentials, https://<servername>/avi Where <servername> is the hostname or IP address of the Avamar system.
- Select the History Tab to check for previously installed hotfixes and patches.
-
Where to find the latest Avamar Security Rollup (Product Security Rollup)
- The Security Rollup can be downloaded from the Avamar Support Site.
- Select the Update kit and download the Platform Security Rollup. Always download the latest file. The example below shows 2020 R4.
Where to find Security Advisories.
- Advisories are posted on the Avamar Support Site.
- Select Advisories and then Security.
Scenario 1: If the latest OS security rollup is not installed, it is required to get it installed first by following the below:
1. How to install Security Rollup:
- Customers with Avamar Hardware (ADS) can reach out to the Avamar scheduling team to install the Security Rollup.
- Customers using Avamar Virtual Edition can download and install the Rollup themselves. Check KB 169784 for more information.
2. Re-run the security scan once Avamar has the latest AvPlatformOSRollup:
- Once Avamar has the latest AvPlatformOSRollup installed, The security scanning tool should be updated with the latest release, and then re-run the scan.
- This is because any scan or manual assessment performed before the latest AvPlatformOSRollup is installed would not provide useful results.
Scenario 2: If the vulnerability is not addressed, open a service request with the Avamar Support team to address the vulnerability by providing the below information:
- The name of the scanning tool being used and the version/update level
- A copy of the scan report
- All information about the business impact (Note: This is typically based on the severity level of the vulnerability)
- Provide the names of the systems and the IPs and ports that are affected, according to the scan report.
- For each vulnerability reported in the scan, provide:
a) A CVE ID (https://nvd.nist.gov/) if not already given in the scan report
b) A web link to the third-party vendor alert, where there is one.
More articles
- KB 169784 - Installing the latest Avamar Platform Security Rollup on the Avamar Proxy and the NetWorker External Proxy
Affected Products
Avamar, Avamar Server, Avamar Virtual EditionProducts
AvamarArticle Properties
Article Number: 000021586
Article Type: How To
Last Modified: 04 Sep 2024
Version: 6
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.