Vulnerability Details CVE-2011-0546
Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.9%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2011-0546
-
cpe:2.3:a:symantec:backup_exec:11.0
-
cpe:2.3:a:symantec:backup_exec:12.0
-
cpe:2.3:a:symantec:backup_exec:12.5
-
cpe:2.3:a:symantec:backup_exec:13.0