6.5
CVSSv2

CVE-2011-0546

Published: 31/05/2011 Updated: 23/08/2016
CVSS v2 Base Score: 6.5 | Impact Score: 10 | Exploitability Score: 2.5
VMScore: 655
Vector: AV:A/AC:H/Au:S/C:C/I:C/A:C

Vulnerability Summary

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle malicious users to execute NDMP commands via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

symantec backup exec 12.0

symantec backup exec 12.5

symantec backup exec 11.0

symantec backup exec 13.0

Exploits

Exploit Title: Symantec Backup Exec MiTM Attack Date: 27/05/2011 Author: Nibin Software Link: wwwsymanteccom/business/products/familyjsp?familyid=backupexec Version: - Symantec Backup Exec for Windows Servers versions 110, 120, and 125 - Symantec Backup Exec 2010 versions 130 and 130 R2 Tested on: Tested on Symantec Backup Exec 12 ...