CVE-2005-2611 describes a critical vulnerability in several Veritas Backup Exec and NetBackup products, including Backup Exec for Windows Servers (versions 8.6-10.0) and NetWare Servers (9.0-9.1), and NetBackup for NetWare Media Server Option (4.5-5.1). The flaw stems from the use of a static password during authentication between the NDMP agent and the backup server. This vulnerability carries a CVSS score of 10.0, indicating maximum severity, as it allows unauthenticated remote attackers to read and write arbitrary files on the backup server, leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit code is publicly available via Metasploit (EDB-1147), demonstrating its exploitability. Despite its age and high risk, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
netware_servers_9.0.4019CPE matchmatch criteria | cpe:2.3:a:symantec_veritas:backup_exec:netware_servers_9.0.4019:*:*:*:*:*:*:* | ||
netware_servers_9.0.4170CPE matchmatch criteria | cpe:2.3:a:symantec_veritas:backup_exec:netware_servers_9.0.4170:*:*:*:*:*:*:* | ||
netware_servers_9.0.4172CPE matchmatch criteria | cpe:2.3:a:symantec_veritas:backup_exec:netware_servers_9.0.4172:*:*:*:*:*:*:* | ||
netware_servers_9.0.4174CPE matchmatch criteria | cpe:2.3:a:symantec_veritas:backup_exec:netware_servers_9.0.4174:*:*:*:*:*:*:* | ||
netware_servers_9.0.4202CPE matchmatch criteria | cpe:2.3:a:symantec_veritas:backup_exec:netware_servers_9.0.4202:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.