« Volver al listado

CVE-2006-4902

Estado: ModificadaAlta (10)—

The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-4902",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-12-14T20:28:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/23368",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1017379",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/threats/247.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/252936",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/21565",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.symantec.com/avcenter/security/Content/2006.12.13a.html",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4999",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27638",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23368",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1017379",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/threats/247.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/252936",
      "tags": [
        "Patch",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/21565",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.symantec.com/avcenter/security/Content/2006.12.13a.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/4999",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27638",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands."
    },
    {
      "lang": "es",
      "value": "El demonio NetBackup bpcd (bpcd.exe) en Symantec Veritas NetBackup 5.0 versiones anteriores a 5.0_MP7, 5.1 versiones anteriores a 5.1_MP6, y 6.0 versiones anteriores a 6.0_MP4, no comprueba apropiadamente comandos encadenados, que permite a atacantes remotos ejecutar código de su elección añadiendo comandos maliciosos en comandos validos."
    }
  ],
  "lastModified": "2026-06-16T22:30:00.250",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_client:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "822B77A6-7088-4378-BF42-72F60BD4FC47"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_client:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C554372-6911-4844-A2CB-81CD714002B7"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_client:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14022872-214B-4185-A126-5934C9EFFC88"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_enterprise_server:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A04B4CF7-ACE9-4F29-A699-2904C9712D4A"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_enterprise_server:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8143B064-3F50-4997-AEBC-712D19D5E69F"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_enterprise_server:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01437FD2-2B60-4B64-AAA9-49D1268528A5"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_server:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4A6955A-F85B-40A8-99E1-74832CAA6B95"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_server:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D72BED3-6F51-45FE-8A9F-3287576D71BC"
            },
            {
              "criteria": "cpe:2.3:a:symantec:veritas_netbackup_server:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4140FD3E-A7D9-4C66-9F5C-73ADE358ED83"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}