PT-2005-3501 · Veritas · Veritas Backup Exec For Windows Servers+2

Published

2005-08-17

·

Updated

2017-07-11

·

CVE-2005-2611

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VERITAS Backup Exec for Windows Servers versions 8.6 through 10.0 VERITAS Backup Exec for NetWare Servers versions 9.0 and 9.1 VERITAS NetBackup for NetWare Media Server Option versions 4.5 through 5.1
Description The issue allows remote attackers to read and write arbitrary files with the backup server due to the use of a static password during authentication from the NDMP agent to the server.
Recommendations For VERITAS Backup Exec for Windows Servers versions 8.6 through 10.0, consider disabling the NDMP agent authentication until a patch is available. For VERITAS Backup Exec for NetWare Servers versions 9.0 and 9.1, restrict access to the backup server to minimize the risk of exploitation. For VERITAS NetBackup for NetWare Media Server Option versions 4.5 through 5.1, avoid using the static password for authentication until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2611

Affected Products

Veritas Backup Exec For Netware Servers
Veritas Backup Exec For Windows Servers
Veritas Netbackup For Netware Media Server Option