peter bassill · operator
$ cve CVE-2011-0546 JSON

CVE-2011-0546 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:A/AC:H/Au:S/C:C/I:C/A:C
EPSS1.61% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2011-05-31
Last modified2026-06-16

Affected (1)

VendorProduct
symantecbackup exec

Public exploits

SourceTitleDate
exploit-dbSymantec Backup Exec 12.5 - Man In The Middle2011-07-09

References

→ the Explorer  ·  watch your stack  ·  NVD