Lucene search

K
cveMitreCVE-2006-4902
HistoryDec 14, 2006 - 8:28 p.m.

CVE-2006-4902

2006-12-1420:28:00
mitre
web.nvd.nist.gov
27
cve-2006-4902
netbackup
bpcd daemon
symantec veritas
remote code execution
nvd
vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.886

Percentile

98.8%

The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.

Affected configurations

Nvd
Node
symantecveritas_netbackup_clientMatch5.0
OR
symantecveritas_netbackup_clientMatch5.1
OR
symantecveritas_netbackup_clientMatch6.0
OR
symantecveritas_netbackup_enterprise_serverMatch5.0
OR
symantecveritas_netbackup_enterprise_serverMatch5.1
OR
symantecveritas_netbackup_enterprise_serverMatch6.0
OR
symantecveritas_netbackup_serverMatch5.0
OR
symantecveritas_netbackup_serverMatch5.1
OR
symantecveritas_netbackup_serverMatch6.0
VendorProductVersionCPE
symantecveritas_netbackup_client5.0cpe:2.3:a:symantec:veritas_netbackup_client:5.0:*:*:*:*:*:*:*
symantecveritas_netbackup_client5.1cpe:2.3:a:symantec:veritas_netbackup_client:5.1:*:*:*:*:*:*:*
symantecveritas_netbackup_client6.0cpe:2.3:a:symantec:veritas_netbackup_client:6.0:*:*:*:*:*:*:*
symantecveritas_netbackup_enterprise_server5.0cpe:2.3:a:symantec:veritas_netbackup_enterprise_server:5.0:*:*:*:*:*:*:*
symantecveritas_netbackup_enterprise_server5.1cpe:2.3:a:symantec:veritas_netbackup_enterprise_server:5.1:*:*:*:*:*:*:*
symantecveritas_netbackup_enterprise_server6.0cpe:2.3:a:symantec:veritas_netbackup_enterprise_server:6.0:*:*:*:*:*:*:*
symantecveritas_netbackup_server5.0cpe:2.3:a:symantec:veritas_netbackup_server:5.0:*:*:*:*:*:*:*
symantecveritas_netbackup_server5.1cpe:2.3:a:symantec:veritas_netbackup_server:5.1:*:*:*:*:*:*:*
symantecveritas_netbackup_server6.0cpe:2.3:a:symantec:veritas_netbackup_server:6.0:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.886

Percentile

98.8%