Veritas NetBackup Information Leakage Vulnerability (CVE-2015-6551)
Veritas NetBackup Information Leakage Vulnerability (CVE-2015-6551)
Release date:
Updated on:
Affected Systems:
Veritas Backup Exec 7.x-7.5.0.7
Veritas Backup Exec 7.6.0.x-7.6.0.4
Veritas NetBackup Appliance <= 2.5.4
Veritas maid <= 2.6.0.4
Description:
CVE (CAN) ID: CVE-2015-6551
Veritas Backup Exec is a data protection and system recovery solution.
Veritas NetBackup 7.x-7.5.0.7, 7.6.0.x-7.6.0.4, and NetBackup Appliance <= 2.5.4, 2.6.0.x <= 2.6.0.4. No TLS is used for data sent from the Management Console to the NBU server, remote attackers can obtain sensitive information by sniffing Key Exchange packets on the network.
<* Source: Emilien Girault
*>
Suggestion:
Vendor patch:
Veritas
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.veritas.com/content/support/en_US/security/VTS16-001.html
This article permanently updates the link address: