PT-2016-3719 · Veritas · Veritas Netbackup+1
Publicado
2016-05-07
·
Atualizado
2016-12-01
·
CVE-2015-6551
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Veritas NetBackup versions 7.x through 7.5.0.7
Veritas NetBackup versions 7.6.0.x through 7.6.0.4
Veritas NetBackup Appliance versions 2.5.4 and earlier
Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4
Description
The issue allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets, as the administration-console traffic to the NBU server does not use TLS.
Recommendations
For Veritas NetBackup versions 7.x through 7.5.0.7, consider implementing TLS for administration-console traffic to the NBU server.
For Veritas NetBackup versions 7.6.0.x through 7.6.0.4, consider implementing TLS for administration-console traffic to the NBU server.
For Veritas NetBackup Appliance versions 2.5.4 and earlier, consider implementing TLS for administration-console traffic to the NBU server.
For Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4, consider implementing TLS for administration-console traffic to the NBU server.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Veritas Netbackup
Veritas Netbackup Appliance