CVE-2005-0358
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.63% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- emc/legato networker · sun/solstice backup · sun/storedge enterprise backup software
- Source
- cret@cert.org
References
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://securitytracker.com/id?1014713Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/407641Patch, Third Party Advisory, US Government Resource
- http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm
- http://www.osvdb.org/18801
- http://www.securityfocus.com/bid/14582Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21892
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://securitytracker.com/id?1014713Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/407641Patch, Third Party Advisory, US Government Resource
- http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm
- http://www.osvdb.org/18801
- http://www.securityfocus.com/bid/14582Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21892
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.