CVE-2005-0357
Last modified
CVE-2005-0357 is a vulnerability of currently unknown severity. EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.. EPSS estimates a 4.50% chance of exploitation in the next 30 days.
Description
EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Legato Networker | 4.2.2 |
| Emc | Legato Networker | 6.0 |
| Emc | Legato Networker | 6.1 |
| Emc | Legato Networker | 7.2 |
| Emc | Legato Networker | 7.13 |
| Sun | Solstice Backup | 6.0 |
| Sun | Solstice Backup | 6.1 |
| Sun | Storedge Enterprise Backup Software | 7.0 |
| Sun | Storedge Enterprise Backup Software | 7.1 |
| Sun | Storedge Enterprise Backup Software | 7.2 |
References
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/606857Patch, Third Party Advisory, US Government Resource
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/606857Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0357?
How severe is CVE-2005-0357?
How do I fix CVE-2005-0357?
Are you affected by CVE-2005-0357?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
