CVE-2005-2611

critical

Description

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/21793

http://www.vupen.com/english/advisories/2005/1387

http://www.us-cert.gov/cas/techalerts/TA05-224A.html

http://www.kb.cert.org/vuls/id/378957

http://securityresponse.symantec.com/avcenter/security/Content/2005.08.12b.html

http://secunia.com/advisories/16403

Details

Source: Mitre, NVD

Published: 2005-08-17

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical