MEDIUM · 6.5

CVE-2011-0546

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute ...

Vulnerability Description

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.

CVSS Score

6.5

MEDIUM

AV:A/AC:H/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
SymantecBackup Exec11.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0546?

CVE-2011-0546 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute ...

How severe is CVE-2011-0546?

CVE-2011-0546 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0546?

Check the references section above for vendor advisories and patch information. Affected products include: Symantec Backup Exec.