SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-2611

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which…

HIGH 10.0EPSS 87.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 87.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
87.03% probability · 100th percentile
CISA KEV
Not listed
Affected
symantec veritas/backup exec · symantec veritas/backup exec remote agent · symantec veritas/netbackup
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.