PT-2005-3501 · Veritas · Veritas Backup Exec For Windows Servers+2
Publicado
2005-08-17
·
Atualizado
2017-07-11
·
CVE-2005-2611
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VERITAS Backup Exec for Windows Servers versions 8.6 through 10.0
VERITAS Backup Exec for NetWare Servers versions 9.0 and 9.1
VERITAS NetBackup for NetWare Media Server Option versions 4.5 through 5.1
Description
The issue allows remote attackers to read and write arbitrary files with the backup server due to the use of a static password during authentication from the NDMP agent to the server.
Recommendations
For VERITAS Backup Exec for Windows Servers versions 8.6 through 10.0, consider disabling the NDMP agent authentication until a patch is available.
For VERITAS Backup Exec for NetWare Servers versions 9.0 and 9.1, restrict access to the backup server to minimize the risk of exploitation.
For VERITAS NetBackup for NetWare Media Server Option versions 4.5 through 5.1, avoid using the static password for authentication until the issue is resolved.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Veritas Backup Exec For Netware Servers
Veritas Backup Exec For Windows Servers
Veritas Netbackup For Netware Media Server Option