« Volver al listado

CVE-2011-0546

Estado: ModificadaMedia (6.5)—

Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-0546",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:H/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 2.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-05-31T20:55:01.563",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=131489365508507&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/44698",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/8300",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/47824",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110526_00",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=131489365508507&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/44698",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/8300",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/47824",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2011&suid=20110526_00",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Symantec Backup Exec v11.0, v12.0, v12.5, v13.0 y v13.0R2 no valida la información de identidad enviada entre el servidor media y el agente remoto, que permite a los atacantes de hombre-en-medio (man in the middle) para ejecutar comandos NDMP a través de de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:27:36.250",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "588376ED-95B0-4A05-B412-F52CDD9E76F4"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B232C57-2543-4E88-96CF-A91B4915DC4F"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:12.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF55A13F-D3C7-4497-869D-2B0EB8FBE3AB"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:13.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71E52C0A-48F6-4349-AF54-1614662996A7"
            },
            {
              "criteria": "cpe:2.3:a:symantec:backup_exec:13.0:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95269E45-6B4B-46D5-AE55-4025ECF60CB5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}