SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-0359

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of…

MEDIUM 6.4EPSS 4.29%

Does this matter?

Lower severity and a low EPSS score (4.29%). Track it; it rarely justifies an emergency change on its own.

Description

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
EPSS
4.29% probability · 91th percentile
CISA KEV
Not listed
Affected
emc/legato networker · sun/solstice backup · sun/storedge enterprise backup software
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.