HIGH · 10.0

CVE-2005-2611

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authe...

Vulnerability Description

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Symantec VeritasBackup Execnetware_servers_9.0.4019
Symantec VeritasBackup Exec Remote Agentnetware_server
Symantec VeritasNetbackupnetware_media_servers_4.5

References

FAQ

What is CVE-2005-2611?

CVE-2005-2611 is a vulnerability with a CVSS score of 10.0 (HIGH). VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authe...

How severe is CVE-2005-2611?

CVE-2005-2611 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2611?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Veritas Backup Exec, Symantec Veritas Backup Exec Remote Agent, Symantec Veritas Netbackup.