PT-2016-3719 · Veritas · Veritas Netbackup+1

Published

2016-05-07

·

Updated

2016-12-01

·

CVE-2015-6551

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions 7.x through 7.5.0.7 Veritas NetBackup versions 7.6.0.x through 7.6.0.4 Veritas NetBackup Appliance versions 2.5.4 and earlier Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4
Description The issue allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets, as the administration-console traffic to the NBU server does not use TLS.
Recommendations For Veritas NetBackup versions 7.x through 7.5.0.7, consider implementing TLS for administration-console traffic to the NBU server. For Veritas NetBackup versions 7.6.0.x through 7.6.0.4, consider implementing TLS for administration-console traffic to the NBU server. For Veritas NetBackup Appliance versions 2.5.4 and earlier, consider implementing TLS for administration-console traffic to the NBU server. For Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4, consider implementing TLS for administration-console traffic to the NBU server.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6551

Affected Products

Veritas Netbackup
Veritas Netbackup Appliance