CVE-2015-6552

CRITICAL

Veritas NetBackup and NetBackup Appliance - Unauthenticated Remote Procedure Call Injection

Title source: llm
STIX 2.1

Description

The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to make arbitrary RPC calls via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035704

Scores

CVSS v3 9.8
EPSS 0.0211
EPSS Percentile 79.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (37)
veritas/netbackup 7.0
veritas/netbackup 7.0.1
veritas/netbackup 7.1.0.1
veritas/netbackup 7.1.0.2
veritas/netbackup 7.1.0.3
veritas/netbackup 7.1.0.4
veritas/netbackup 7.5.0.1
veritas/netbackup 7.5.0.3
veritas/netbackup 7.5.0.4
veritas/netbackup 7.5.0.5
... and 27 more
Published May 07, 2016
Tracked Since Feb 18, 2026