CVE-2005-0359
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of…
Does this matter?
Lower severity and a low EPSS score (4.29%). Track it; it rarely justifies an emergency change on its own.
Description
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
- EPSS
- 4.29% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- emc/legato networker · sun/solstice backup · sun/storedge enterprise backup software
- Source
- cret@cert.org
References
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://securitytracker.com/id?1014713Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/801089Patch, Third Party Advisory, US Government Resource
- http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htmPatch
- http://www.osvdb.org/18802
- http://www.securityfocus.com/bid/14582Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21893
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://securitytracker.com/id?1014713Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/801089Patch, Third Party Advisory, US Government Resource
- http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htmPatch
- http://www.osvdb.org/18802
- http://www.securityfocus.com/bid/14582Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21893
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.