This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Veritas First view 2016-05-07
Product Netbackup Appliance Last view 2024-03-07
Version 2.6.1 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:veritas:netbackup_appliance

Activity : Overall

Related : CVE

  Date Alert Description
9.8 2024-03-07 CVE-2024-28222

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.

7.2 2023-06-29 CVE-2023-37237

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.

7.2 2019-03-21 CVE-2019-9868

An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.

7.2 2019-03-21 CVE-2019-9867

An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is displayed to an administrator.

7.2 2018-10-25 CVE-2018-18652

A remote command execution vulnerability in Veritas NetBackup Appliance before 3.1.2 allows authenticated administrators to execute arbitrary commands as root. This issue was caused by insufficient filtering of user provided input.

9.8 2017-05-09 CVE-2017-8859

In Veritas NetBackup Appliance 3.0 and earlier, unauthenticated users can execute arbitrary commands as root.

9.8 2017-05-09 CVE-2017-8858

In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' process.

9.8 2017-05-09 CVE-2017-8857

In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command execution using the 'bprd' process.

9.8 2017-05-09 CVE-2017-8856

In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the 'bprd' process.

9.8 2017-03-02 CVE-2017-6409

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access.

7 2017-03-02 CVE-2017-6408

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.

8.8 2017-03-02 CVE-2017-6407

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.

8.8 2017-03-02 CVE-2017-6406

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.

7.5 2017-03-02 CVE-2017-6405

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Hostname-based security is open to DNS spoofing.

5.5 2017-03-02 CVE-2017-6404

An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction or spoofing of log data.

9.8 2017-03-02 CVE-2017-6403

An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.

6.5 2017-03-02 CVE-2017-6402

An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Denial of service affecting NetBackup server can occur.

7.8 2017-03-02 CVE-2017-6401

An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bpcd and bpnbat.

8.8 2017-03-02 CVE-2017-6400

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on NetBackup Server and Client can occur (on the local system).

8.8 2017-03-02 CVE-2017-6399

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.

9.8 2016-05-07 CVE-2015-6552

The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to make arbitrary RPC calls via unspecified vectors.

5.9 2016-05-07 CVE-2015-6551

Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS for administration-console traffic to the NBU server, which allows remote attackers to obtain sensitive information by sniffing the network for key-exchange packets.

9.8 2016-05-07 CVE-2015-6550

bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary commands via crafted input.

CWE : Common Weakness Enumeration

%idName
25% (4) CWE-732 Incorrect Permission Assignment for Critical Resource
12% (2) CWE-522 Insufficiently Protected Credentials
12% (2) CWE-284 Access Control (Authorization) Issues
6% (1) CWE-798 Use of Hard-coded Credentials
6% (1) CWE-362 Race Condition
6% (1) CWE-306 Missing Authentication for Critical Function
6% (1) CWE-290 Authentication Bypass by Spoofing
6% (1) CWE-276 Incorrect Default Permissions
6% (1) CWE-269 Improper Privilege Management
6% (1) CWE-200 Information Exposure
6% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...

Snort® IPS/IDS

Date Description
2017-07-04 NetBackup bprd remote file write attempt
RuleID : 43064 - Type : SERVER-OTHER - Revision : 2
2017-07-04 Veritas Netbackup bprd remote code execution attempt
RuleID : 43055 - Type : SERVER-OTHER - Revision : 2

Nessus® Vulnerability Scanner

id Description
2017-11-30 Name: The remote backup management appliance is affected by multiple vulnerabilities.
File: veritas_netbackup_appliance_VTS17-003.nasl - Type: ACT_GATHER_INFO
2017-05-22 Name: The remote backup management appliance is affected by a remote command execut...
File: veritas_netbackup_appliance_VTS17-005_exploit.nasl - Type: ACT_ATTACK
2017-05-18 Name: A back-up management application installed on the remote host is affected by ...
File: veritas_netbackup_VTS17-004.nasl - Type: ACT_GATHER_INFO
2017-05-18 Name: The remote backup management appliance is affected by a remote command execut...
File: veritas_netbackup_appliance_VTS17-005.nasl - Type: ACT_GATHER_INFO
2016-05-13 Name: The remote host has a back-up management application installed that is affect...
File: veritas_netbackup_VTS16-001.nasl - Type: ACT_GATHER_INFO