peter bassill · operator
$ cve CVE-2005-2611 JSON

CVE-2005-2611 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 87% (pctl 100)

Patch early

A public exploit exists.

Description

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS87.03% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2005-08-17
Last modified2026-06-16

Affected (3)

VendorProduct
symantec veritasbackup exec
symantec veritasbackup exec remote agent
symantec veritasnetbackup

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD