PT-2005-3501 · Veritas · Veritas Backup Exec For Windows Servers+2
Published
2005-08-17
·
Updated
2017-07-11
·
CVE-2005-2611
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VERITAS Backup Exec for Windows Servers versions 8.6 through 10.0
VERITAS Backup Exec for NetWare Servers versions 9.0 and 9.1
VERITAS NetBackup for NetWare Media Server Option versions 4.5 through 5.1
Description
The issue allows remote attackers to read and write arbitrary files with the backup server due to the use of a static password during authentication from the NDMP agent to the server.
Recommendations
For VERITAS Backup Exec for Windows Servers versions 8.6 through 10.0, consider disabling the NDMP agent authentication until a patch is available.
For VERITAS Backup Exec for NetWare Servers versions 9.0 and 9.1, restrict access to the backup server to minimize the risk of exploitation.
For VERITAS NetBackup for NetWare Media Server Option versions 4.5 through 5.1, avoid using the static password for authentication until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veritas Backup Exec For Netware Servers
Veritas Backup Exec For Windows Servers
Veritas Netbackup For Netware Media Server Option