6.5

CVE-2011-0546

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec ≫ Backup Exec Version 11.0
Symantec ≫ Backup Exec Version 12.0
Symantec ≫ Backup Exec Version 12.5
Symantec ≫ Backup Exec Version 13.0
Symantec ≫ Backup Exec Version 13.0 Update r2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.61% 0.727
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.5 10
AV:A/AC:H/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://marc.info/?l=bugtraq&m=131489365508507&w=2
http://secunia.com/advisories/44698
Vendor Advisory
http://securityreason.com/securityalert/8300
http://www.securityfocus.com/bid/47824
http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110526_00