Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801798
Category:General
Title:Symantec Backup Exec Products Arbitrary Command Execution vulnerability
Summary:Symantec Backup Exec Products is prone to an arbitrary command execution vulnerability.
Description:Summary:
Symantec Backup Exec Products is prone to an arbitrary command execution vulnerability.

Vulnerability Insight:
The flaw is due to weakness in communication protocol implementation
and lack of validation of identity information exchanged between media server and remote agent.

Vulnerability Impact:
Successful exploitation will allow remote attackers to cause privilege
escalation by executing post authentication NDMP commands.

Affected Software/OS:
Symantec Backup Exec for Windows Servers versions 11.0, 12.0, 12.5
Symantec Backup Exec 2010 versions 13.0, 13.0 R2

Solution:
Upgrade to the Symantec Backup Exec 2010 R3

CVSS Score:
6.5

CVSS Vector:
AV:A/AC:H/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0546
BugTraq ID: 47824
http://www.securityfocus.com/bid/47824
HPdes Security Advisory: HPSBUX02700
http://marc.info/?l=bugtraq&m=131489365508507&w=2
HPdes Security Advisory: SSRT100506
http://secunia.com/advisories/44698
http://securityreason.com/securityalert/8300
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.