CVE-2011-0546

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:backup_exec:11.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:12.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:12.5:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:13.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:13.0:r2:*:*:*:*:*:*

History

No history.

Information

Published : 2011-05-31 20:55

Updated : 2024-02-04 17:54


NVD link : CVE-2011-0546

Mitre link : CVE-2011-0546

CVE.ORG link : CVE-2011-0546


JSON object : View

Products Affected

symantec

  • backup_exec
CWE
CWE-20

Improper Input Validation