CVE-2005-0357
Last modified
CVE-2005-0357 is a vulnerability of currently unknown severity. EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.. EPSS estimates a 4.50% chance of exploitation in the next 30 days.
Description
EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Legato Networker | 4.2.2 |
| Emc | Legato Networker | 6.0 |
| Emc | Legato Networker | 6.1 |
| Emc | Legato Networker | 7.2 |
| Emc | Legato Networker | 7.13 |
| Sun | Solstice Backup | 6.0 |
| Sun | Solstice Backup | 6.1 |
| Sun | Storedge Enterprise Backup Software | 7.0 |
| Sun | Storedge Enterprise Backup Software | 7.1 |
| Sun | Storedge Enterprise Backup Software | 7.2 |
References
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/606857Patch, Third Party Advisory, US Government Resource
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/606857Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0357?
How severe is CVE-2005-0357?
How do I fix CVE-2005-0357?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0349The production release of the UniversalAgent for UNIX in Bri…
- CVE-2005-0350Heap-based buffer overflow in multiple F-Secure Anti-Virus a…
- CVE-2005-0351Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh…
- CVE-2005-0352Servers Alive 4.1 and 5.0, when running as a service, does n…
- CVE-2005-0353Buffer overflow in the Sentinel LM (Lservnt) service in the …
- CVE-2005-0356Multiple TCP implementations with Protection Against Wrapped…
- CVE-2005-0358EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorE…
- CVE-2005-0359The Legato PortMapper in EMC Legato NetWorker, Sun Solstice …
- CVE-2005-0360The Microsoft Log Sink Class ActiveX control in pkmcore.dll …
- CVE-2005-0362awstats.pl in AWStats 6.2 allows remote attackers to execute…
- CVE-2005-0363awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to…
- CVE-2005-0364Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.1…
Are you affected by CVE-2005-0357?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
