Vulnerability Name: | CVE-2008-5407 (CCN-46730) | ||||||||
Assigned: | 2008-11-19 | ||||||||
Published: | 2008-11-19 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.4 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:C) 7.0 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-5407 Source: CCN Type: SA32810 Symantec Backup Exec for Windows Servers Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 32810 Source: CCN Type: SYM08-021 Symantec Backup Exec Authentication Bypass and Potential Buffer Overflow Source: CONFIRM Type: Patch, Vendor Advisory http://securityresponse.symantec.com/avcenter/security/Content/2008.11.19.html Source: CCN Type: SECTRACK ID: 1021246 Symantec Backup Exec Lets Remote Users Bypass Authentication and Execute Arbitrary Code on the Target System Source: CONFIRM Type: Patch, Vendor Advisory http://seer.entsupport.symantec.com/docs/314528.htm Source: CCN Type: OSVDB ID: 49980 Symantec Backup Exec for Windows Server Authentication Multiple Unspecified Issues Source: BID Type: UNKNOWN 32347 Source: CCN Type: BID-32347 Symantec Backup Exec for Windows Server Remote Agent Authentication Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1021246 Source: VUPEN Type: UNKNOWN ADV-2008-3209 Source: XF Type: UNKNOWN backupexec-remoteagent-security-bypass(46730) Source: XF Type: UNKNOWN backupexec-remoteagent-security-bypass(46730) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |