PT-2016-3719 · Veritas · Veritas Netbackup+1
Published
2016-05-07
·
Updated
2016-12-01
·
CVE-2015-6551
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Veritas NetBackup versions 7.x through 7.5.0.7
Veritas NetBackup versions 7.6.0.x through 7.6.0.4
Veritas NetBackup Appliance versions 2.5.4 and earlier
Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4
Description
The issue allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets, as the administration-console traffic to the NBU server does not use TLS.
Recommendations
For Veritas NetBackup versions 7.x through 7.5.0.7, consider implementing TLS for administration-console traffic to the NBU server.
For Veritas NetBackup versions 7.6.0.x through 7.6.0.4, consider implementing TLS for administration-console traffic to the NBU server.
For Veritas NetBackup Appliance versions 2.5.4 and earlier, consider implementing TLS for administration-console traffic to the NBU server.
For Veritas NetBackup Appliance versions 2.6.0.x through 2.6.0.4, consider implementing TLS for administration-console traffic to the NBU server.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veritas Netbackup
Veritas Netbackup Appliance