CVE-2011-0546

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:symantec:backup_exec:11.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:12.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:12.5:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:13.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:backup_exec:13.0:r2:*:*:*:*:*:*

History

21 Nov 2024, 01:24

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=131489365508507&w=2 - () http://marc.info/?l=bugtraq&m=131489365508507&w=2 -
References () http://secunia.com/advisories/44698 - Vendor Advisory () http://secunia.com/advisories/44698 - Vendor Advisory
References () http://securityreason.com/securityalert/8300 - () http://securityreason.com/securityalert/8300 -
References () http://www.securityfocus.com/bid/47824 - () http://www.securityfocus.com/bid/47824 -
References () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110526_00 - () http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110526_00 -

Information

Published : 2011-05-31 20:55

Updated : 2024-11-21 01:24


NVD link : CVE-2011-0546

Mitre link : CVE-2011-0546

CVE.ORG link : CVE-2011-0546


JSON object : View

Products Affected

symantec

  • backup_exec
CWE
CWE-20

Improper Input Validation