Vulnerabilities > CVE-2005-2611 - Unspecified vulnerability in Symantec Veritas Backup Exec, Backup Exec Remote Agent and Netbackup
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.
Vulnerable Configurations
Exploit-Db
description | Veritas Backup Exec Remote File Access Exploit (windows). CVE-2005-2611. Remote exploit for windows platform |
id | EDB-ID:1147 |
last seen | 2016-01-31 |
modified | 2005-08-11 |
published | 2005-08-11 |
reporter | N/A |
source | https://www.exploit-db.com/download/1147/ |
title | Veritas Backup Exec Remote File Access Exploit windows |
Metasploit
description | This module abuses a logic flaw in the Backup Exec Windows Agent to download arbitrary files from the system. This flaw was found by someone who wishes to remain anonymous and affects all known versions of the Backup Exec Windows Agent. The output file is in 'MTF' format, which can be extracted by the 'NTKBUp' program listed in the references section. To transfer an entire directory, specify a path that includes a trailing backslash. |
id | MSF:AUXILIARY/ADMIN/BACKUPEXEC/DUMP |
last seen | 2020-05-22 |
modified | 2020-05-12 |
published | 2006-12-03 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/admin/backupexec/dump.rb |
title | Veritas Backup Exec Windows Remote File Access |
Nessus
NASL family | Misc. |
NASL id | VERITAS_AGENT_DEFAULT_ACCOUNT.NASL |
description | The remote host is running a version of VERITAS Backup Exec Agent which is configured with a default root account. An attacker may exploit this flaw to retrieve files from the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 19427 |
published | 2005-08-12 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/19427 |
title | VERITAS Backup Exec Remote Agent Static Password Arbitrary File Download |
code |
|
References
- http://secunia.com/advisories/16403
- http://securityresponse.symantec.com/avcenter/security/Content/2005.08.12b.html
- http://securitytracker.com/id?1014662
- http://www.kb.cert.org/vuls/id/378957
- http://www.securityfocus.com/bid/14551
- http://www.us-cert.gov/cas/techalerts/TA05-224A.html
- http://www.vupen.com/english/advisories/2005/1387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21793