CVE-2005-2611

UnknownEPSS 87.03%

Last modified

CVE-2005-2611 is a vulnerability of currently unknown severity. VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.. EPSS estimates a 87.03% chance of exploitation in the next 30 days.

Description

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

Metrics

EPSS Probability
87.03%

99.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Symantec VeritasBackup Execnetware_servers_9.0.4019
Symantec VeritasBackup Execnetware_servers_9.0.4170
Symantec VeritasBackup Execnetware_servers_9.0.4172
Symantec VeritasBackup Execnetware_servers_9.0.4174
Symantec VeritasBackup Execnetware_servers_9.0.4202
Symantec VeritasBackup Execnetware_servers_9.1.306
Symantec VeritasBackup Execnetware_servers_9.1.307
Symantec VeritasBackup Execnetware_servers_9.1.1067_.2
Symantec VeritasBackup Execnetware_servers_9.1.1067_.3
Symantec VeritasBackup Execnetware_servers_9.1.1127_.1
Symantec VeritasBackup Execnetware_servers_9.1.1151_.1
Symantec VeritasBackup Execnetware_servers_9.1.1152
Symantec VeritasBackup Execnetware_servers_9.1.1152_.4
Symantec VeritasBackup Execnetware_servers_9.1.1154
Symantec VeritasBackup Execnetware_servers_9.1.1156
Symantec VeritasBackup Execwindows_servers_8.6
Symantec VeritasBackup Execwindows_servers_9.0
Symantec VeritasBackup Execwindows_servers_9.0_rev._4367
Symantec VeritasBackup Execwindows_servers_9.0_rev._4367_sp1
Symantec VeritasBackup Execwindows_servers_9.0_rev._4454
Symantec VeritasBackup Execwindows_servers_9.0_rev._4454_sp1
Symantec VeritasBackup Execwindows_servers_9.1
Symantec VeritasBackup Execwindows_servers_9.1_rev._4691
Symantec VeritasBackup Execwindows_servers_9.1_rev._4691_sp2
Symantec VeritasBackup Execwindows_servers_10.0_rev._5484
Symantec VeritasBackup Execwindows_servers_10.0_rev._5484_sp1
Symantec VeritasBackup Execwindows_servers_10.0_rev._5520
Symantec VeritasBackup Exec Remote Agentnetware_server
Symantec VeritasBackup Exec Remote Agentunix_linux_server
Symantec VeritasBackup Exec Remote Agentwindows_server
Symantec VeritasNetbackupnetware_media_servers_4.5
Symantec VeritasNetbackupnetware_media_servers_4.5_fp1
Symantec VeritasNetbackupnetware_media_servers_4.5_fp2
Symantec VeritasNetbackupnetware_media_servers_4.5_fp3
Symantec VeritasNetbackupnetware_media_servers_4.5_fp4
Symantec VeritasNetbackupnetware_media_servers_4.5_fp5
Symantec VeritasNetbackupnetware_media_servers_4.5_fp6
Symantec VeritasNetbackupnetware_media_servers_4.5_fp7
Symantec VeritasNetbackupnetware_media_servers_4.5_fp8
Symantec VeritasNetbackupnetware_media_servers_4.5_mp1
Symantec VeritasNetbackupnetware_media_servers_4.5_mp2
Symantec VeritasNetbackupnetware_media_servers_4.5_mp3
Symantec VeritasNetbackupnetware_media_servers_4.5_mp4
Symantec VeritasNetbackupnetware_media_servers_4.5_mp5
Symantec VeritasNetbackupnetware_media_servers_4.5_mp6
Symantec VeritasNetbackupnetware_media_servers_4.5_mp7
Symantec VeritasNetbackupnetware_media_servers_4.5_mp8
Symantec VeritasNetbackupnetware_media_servers_5.0
Symantec VeritasNetbackupnetware_media_servers_5.0_mp1
Symantec VeritasNetbackupnetware_media_servers_5.0_mp2

Showing 50 of 57 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-2611?
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.
How severe is CVE-2005-2611?
Severity scoring for CVE-2005-2611 is pending analysis. The EPSS model estimates a 87.03% probability of exploitation in the next 30 days.
How do I fix CVE-2005-2611?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-2611?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST