PT-2016-3719 · Veritas · Veritas Netbackup+1

Publicado

2016-05-07

·

Atualizado

2016-12-01

·

CVE-2015-6551

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions 7.x through 7.5.0.7 Veritas NetBackup versions 7.6.0.x through 7.6.0.4 Veritas NetBackup Appliance versions 2.5.4 and earlier Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4
Description The issue allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets, as the administration-console traffic to the NBU server does not use TLS.
Recommendations For Veritas NetBackup versions 7.x through 7.5.0.7, consider implementing TLS for administration-console traffic to the NBU server. For Veritas NetBackup versions 7.6.0.x through 7.6.0.4, consider implementing TLS for administration-console traffic to the NBU server. For Veritas NetBackup Appliance versions 2.5.4 and earlier, consider implementing TLS for administration-console traffic to the NBU server. For Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4, consider implementing TLS for administration-console traffic to the NBU server.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6551

Produtos afetados

Veritas Netbackup
Veritas Netbackup Appliance