← Vulnerability feed

Vulnerability record · CVE-2005-0771 · published 23 June 2005

CVE-2005-0771: VERITAS Backup Exec Server RPC interface allows unauthenticated registry modification

SSymantec Veritas · Backup Exec

The VERITAS Backup Exec Server (beserver.exe) versions 9.0 through 10.0 for Windows exposes an RPC interface on TCP port 6106 that permits remote, unauthenticated callers to modify the Windows registry. Because the flaw is reachable over the network with no credentials and yields full confidentiality, integrity and availability impact, it is a severe pre-authentication remote compromise of the backup server host.

10.0 CVSS 2.0 High EPSS 54% · top 1.0%
10.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote access to an RPC interface that permits registry modification gives complete host compromise with a CVSS 2.0 score of 10 and a high EPSS percentile.

What it is

The VERITAS Backup Exec Server (beserver.exe) versions 9.0 through 10.0 for Windows exposes an RPC interface on TCP port 6106 that permits remote, unauthenticated callers to modify the Windows registry. Because the flaw is reachable over the network with no credentials and yields full confidentiality, integrity and availability impact, it is a severe pre-authentication remote compromise of the backup server host.

Impact

An attacker can alter registry keys on the Backup Exec server, which can subvert the service's configuration and, in practice, lead to full control of the host. The CVSS 2.0 vector (AV:N/AC:L/Au:N/C:C/I:C/A:C) rates the impact as complete across confidentiality, integrity and availability.

Attack surface

Reached remotely over the network via the RPC interface on TCP port 6106; the description states no authentication is required and no user interaction is mentioned. Any host that can route to port 6106 on a vulnerable Backup Exec server is a potential entry point.

Exploitation

The record does not list this CVE in CISA KEV and no ransomware usage is documented; EPSS is high at 0.54155 (98.9th percentile), and multiple references carry Patch and Vendor Advisory tags, indicating a fix exists but no confirmed in-the-wild exploitation is recorded here.

What to do

  • Apply the vendor patch referenced in the VERITAS/Symantec advisories and CERT/CC VU#584505 as the first action.
  • Block or restrict TCP port 6106 to trusted management hosts only, using host firewalls or network ACLs.
  • Isolate Backup Exec servers on a dedicated management segment so the RPC interface is not reachable from general user or internet-facing networks.
  • If the affected 9.0-10.0 versions cannot be patched, upgrade to a supported Backup Exec release.
  • Monitor and alert on unexpected registry changes on Backup Exec hosts.

Detection

  • Monitor network flows for inbound connections to TCP port 6106 on Backup Exec servers from untrusted sources.
  • Audit Windows registry change events on Backup Exec hosts and alert on modifications to Backup Exec service keys.
  • Correlate beserver.exe process activity with unexpected registry writes or service configuration changes.
  • Review Backup Exec server logs for anomalous RPC method invocations around the time of registry changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0771 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2611VERITAS Backup Exec and NetBackup NDMP agent static password flawThe NDMP agent in VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Me…EPSS 87%analysed10.0CVE-2004-1172Veritas Backup Exec Agent Browser stack buffer overflow via long hostnameThe Agent Browser component in Veritas Backup Exec 8.x and 9.x has a stack-based buffer overflow triggered by a registration request containing an ov…EPSS 82%analysed7.5CVE-2005-2079Symantec veritas backup exec vulnerabilityHeap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to exec…EPSS 5.2%7.5CVE-2005-2080Symantec veritas backup exec vulnerabilityUnknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 fo…EPSS 1.5%7.5CVE-2005-2051Symantec veritas backup exec vulnerabilityBuffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbi…EPSS 3.2%7.5CVE-2005-0773VERITAS Backup Exec Remote Agent stack buffer overflow via CONNECT_CLIENT_AUTHVERITAS Backup Exec Remote Agent (9.0 through 10.0 on Windows, 9.0.4019 through 9.1.307 on NetWare) has a stack-based buffer overflow triggered by a …EPSS 86%analysed6.5CVE-2006-4128Symantec veritas backup exec vulnerabilityMultiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Bac…EPSS 5.8%5.0CVE-2006-1297Symantec veritas backup exec vulnerabilityUnspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2005-0771), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.