Vulnerability Description
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to make arbitrary RPC calls via unspecified vectors.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Veritas | Netbackup Appliance | 1.1.0.1 |
| Veritas | Netbackup | 7.0 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1035704
- https://www.veritas.com/content/support/en_US/security/VTS16-001.htmlVendor Advisory
- http://www.securitytracker.com/id/1035704
- https://www.veritas.com/content/support/en_US/security/VTS16-001.htmlVendor Advisory
FAQ
What is CVE-2015-6552?
CVE-2015-6552 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4...
How severe is CVE-2015-6552?
CVE-2015-6552 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-6552?
Check the references section above for vendor advisories and patch information. Affected products include: Veritas Netbackup Appliance, Veritas Netbackup.