Vulnerability record · CVE-2005-0773 · published 18 June 2005
CVE-2005-0773: VERITAS Backup Exec Remote Agent stack buffer overflow via CONNECT_CLIENT_AUTH
SSymantec Veritas · Backup Exec
VERITAS Backup Exec Remote Agent (9.0 through 10.0 on Windows, 9.0.4019 through 9.1.307 on NetWare) has a stack-based buffer overflow triggered by a CONNECT_CLIENT_AUTH request using authentication method type 3 (Windows credentials) with an overly long password argument. Because the flaw is remotely reachable and pre-authentication, it exposes backup servers to arbitrary code execution.
Description
Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit code and very high EPSS, though the product is legacy and not in KEV.
What it is
VERITAS Backup Exec Remote Agent (9.0 through 10.0 on Windows, 9.0.4019 through 9.1.307 on NetWare) has a stack-based buffer overflow triggered by a CONNECT_CLIENT_AUTH request using authentication method type 3 (Windows credentials) with an overly long password argument. Because the flaw is remotely reachable and pre-authentication, it exposes backup servers to arbitrary code execution.
Impact
A remote attacker can execute arbitrary code on the affected Backup Exec Remote Agent, potentially with the privileges of the service, leading to full compromise of the backup server and any data or credentials it holds.
Attack surface
Reached over the network via the Remote Agent service (CVSS vector AV:N/AC:L/Au:N), requiring no authentication and no user interaction; the attacker only needs to send a crafted CONNECT_CLIENT_AUTH request with a long password.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.864, 99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.
What to do
- Apply the vendor patches referenced in the VERITAS/Symantec advisories (seer.support.veritas.com docs 276604 and 277429) and CERT/US-CERT guidance.
- Restrict network access to the Backup Exec Remote Agent port to trusted management hosts only.
- Disable or stop the Remote Agent service on hosts that do not require it.
- Monitor vendor advisories for updated builds and verify installed agent versions against the affected ranges.
Detection
- Inspect Remote Agent traffic for CONNECT_CLIENT_AUTH requests carrying authentication method type 3 with abnormally long password fields.
- Alert on Remote Agent service crashes or restarts, which may indicate a failed overflow attempt.
- Monitor for unexpected processes or outbound connections originating from backup servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0773 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0773), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.