Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Veritas Backup Exec 安全漏洞
Vulnerability Description
Veritas Technologies Veritas Backup Exec是美国Veritas Technologies公司的一套功能强大的数据备份恢复工具。该软件拥有基于web的管理控制台和带有易用向导的直观图形用户界面,可以简化安装过程,提高可管理性。高性能代理和选件,具有快速保护台式电脑、笔记本电脑和服务器数据的灵活性。可以为Microsoft Windows服务器环境提供经过认证的、全面的、经济高效的保护。 Veritas Backup Exec before 21.2 存在安全漏洞,攻击者
CVSS Information
N/A
Vulnerability Type
N/A