Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Symantec Backup Exec非法访问漏洞
Vulnerability Description
Symantec Backup Exec是美国赛门铁克(Symantec)公司的一套业务备份解决方案。该解决方案为虚拟和物理环境提供数据保护和系统恢复功能。 Windows Servers的Symantec Backup Exec中存在非法访问漏洞。在Backup Exec媒体服务器和远程代理之前实施通讯协议的方式中存在MiTM问题,此问题源于缺少媒体服务器和远程代理之前的身份信息验证,攻击者可以利用该漏洞绕过认证,并执行任意NDMP命令。
CVSS Information
N/A
Vulnerability Type
N/A