← Vulnerability feed

Vulnerability record · CVE-2005-0359 · published 23 August 2005

CVE-2005-0359: Emc legato networker vulnerability

Emc · Legato Networker

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.

6.4 CVSS 2.0 Medium EPSS 4.3% · top 9.2%
6.4CVSS 2.0 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.

AV:N/AC:L/Au:N/C:P/I:N/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0359 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-2754Ibm informix dynamic server vulnerabilityInteger signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe)…EPSS 40%9.3CVE-2007-3618Emc legato networker vulnerabilityStack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute ar…EPSS 7.1%7.5CVE-2005-3658Emc legato networker memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Sols…EPSS 5.2%7.5CVE-2005-0357Emc legato networker vulnerabilityEMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies …EPSS 4.5%7.5CVE-2005-0358Emc legato networker vulnerabilityEMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which…EPSS 4.6%5.0CVE-2005-3659Emc legato networker vulnerabilitynsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.…EPSS 2.5%2.1CVE-2000-0069Sun solstice backup vulnerabilityThe recover program in Solstice Backup allows local users to restore sensitive files.EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2005-0359), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.