Symantec Backup Exec for Windows Multiple Vulnerabilities

critical Nessus Plugin ID 34820

Synopsis

It is possible to bypass authentication in the remote backup agent.

Description

The remote host is running a version of VERITAS Backup Exec Agent that is affected by multiple authentication bypass issues.

An attacker can exploit these issues to manage the backup agent or to execute commands with high privileges.

Solution

Apply the appropriate hotfix referenced in the vendor advisory.

See Also

http://www.symantec.com/avcenter/security/Content/2008.11.19.html

Plugin Details

Severity: Critical

ID: 34820

File Name: veritas_agent_bypass.nbin

Version: 1.80

Type: remote

Agent: windows

Family: Windows

Published: 11/20/2008

Updated: 3/19/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/19/2008

Vulnerability Publication Date: 11/19/2008

Reference Information

CVE: CVE-2008-5407, CVE-2008-5408

BID: 32346, 32347

CWE: 119