Vulnerability Note VU#407641
EMC Legato NetWorker database services use insufficient authentication
Overview
The EMC Legato NetWorker database services use weak authentication, allowing a remote attacker to gain root access to the server.
Description
EMC Legato NetWorker is a cross-platform backup and recovery application. It is also repackaged by Sun Microsystems as Solstice Backup and StorEdge Enterprise Backup, by FSC as Fujitsu Siemens Computers' NetWorker, by NEC as WebSAM NetWorker Powered by Legato, and by Fujitsu as NetWorker. NetWorker database services |
Impact
An unauthenticated, remote attacker could execute arbitrary commands on the NetWorker server as root. Once the NetWorker server has been compromised, any NetWorker client machine could in turn be compromised. |
Solution
Apply a patch or upgrade |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| EMC Software | Affected | 03 Jun 2005 | 16 Aug 2005 |
| Fujitsu Limited | Affected | 15 Aug 2005 | 24 Aug 2005 |
| NEC | Affected | 15 Aug 2005 | 24 Aug 2005 |
| Sun Microsystems, Inc. | Affected | 12 Jul 2005 | 19 Sep 2005 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.legato.com/support/websupport/product_alerts/081605_NW-7x.htm
- http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1
- http://www.legato.com/support/websupport/tech_bulletins/?includefile=388.html
- http://www.legato.com/products/networker/
- http://secunia.com/advisories/16464/
- http://secunia.com/advisories/16470/
- http://www.cnn.com/2005/TECH/internet/07/25/hackers.backup.software.reut/index.html
Credit
Thanks to the NOAA NCIRT Lab for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
- CVE IDs: CAN-2005-0358
- Date Public: 16 Aug 2005
- Date First Published: 16 Aug 2005
- Date Last Updated: 04 Oct 2005
- Severity Metric: 14.63
- Document Revision: 27
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.