CVE-2005-2611 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 87% (pctl 100)
Patch early
A public exploit exists.
Description
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 87.03% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-08-17 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| symantec veritas | backup exec |
| symantec veritas | backup exec remote agent |
| symantec veritas | netbackup |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Veritas Backup Exec (Windows) - Remote File Access (Metasploit) | 2005-08-11 |
References
- http://secunia.com/advisories/16403
- http://securityresponse.symantec.com/avcenter/security/Content/2005.08.12b.html
- http://securitytracker.com/id?1014662
- http://www.kb.cert.org/vuls/id/378957
- http://www.securityfocus.com/bid/14551
- http://www.us-cert.gov/cas/techalerts/TA05-224A.html
- http://www.vupen.com/english/advisories/2005/1387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21793
- http://secunia.com/advisories/16403
- http://securityresponse.symantec.com/avcenter/security/Content/2005.08.12b.html
- http://securitytracker.com/id?1014662
- http://www.kb.cert.org/vuls/id/378957
- http://www.securityfocus.com/bid/14551
- http://www.us-cert.gov/cas/techalerts/TA05-224A.html
- http://www.vupen.com/english/advisories/2005/1387
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21793
→ the Explorer · watch your stack · NVD