← Vulnerability feed

Vulnerability record · CVE-2005-2611 · published 17 August 2005

CVE-2005-2611: VERITAS Backup Exec and NetBackup NDMP agent static password flaw

SSymantec Veritas · Backup Exec

The NDMP agent in VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 authenticates to the backup server using a static password. Because the credential is fixed and shared, anyone who can reach the NDMP service can impersonate the agent and gain the backup server's file access.

10.0 CVSS 2.0 High EPSS 87% · top 0.3%
10.0CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network access yielding complete confidentiality and integrity impact, with high EPSS and public exploit references.

What it is

The NDMP agent in VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 authenticates to the backup server using a static password. Because the credential is fixed and shared, anyone who can reach the NDMP service can impersonate the agent and gain the backup server's file access.

Impact

An attacker gains read and write access to arbitrary files through the backup server, effectively full control over backed-up data and potentially the server itself.

Attack surface

Reachable over the network via the NDMP agent-to-server authentication path; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.87026 (99.7th percentile) and multiple references carry an Exploit tag, indicating public exploit material exists.

What to do

  • Apply the vendor patches referenced in the Symantec and Secunia advisories.
  • Restrict network access to NDMP agent and backup server ports to trusted management hosts only.
  • Replace the static NDMP credential with a unique, rotated secret where the product version allows it.
  • Segment backup infrastructure from general user and internet-reachable networks.
  • Monitor vendor advisories for end-of-life status and migrate off unsupported versions.

Detection

  • Alert on NDMP connections to backup servers from hosts outside the known agent inventory.
  • Baseline and monitor file read/write activity on backup servers for unexpected access patterns.
  • Review backup server logs for authentication from unexpected source addresses or repeated agent logins.
  • Hunt for NDMP traffic on non-standard or externally facing interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2611 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3116Symantec veritas netbackup vulnerabilityStack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and …EPSS 28%10.0CVE-2005-0771VERITAS Backup Exec Server RPC interface allows unauthenticated registry modificationThe VERITAS Backup Exec Server (beserver.exe) versions 9.0 through 10.0 for Windows exposes an RPC interface on TCP port 6106 that permits remote, un…EPSS 54%analysed10.0CVE-2004-1172Veritas Backup Exec Agent Browser stack buffer overflow via long hostnameThe Agent Browser component in Veritas Backup Exec 8.x and 9.x has a stack-based buffer overflow triggered by a registration request containing an ov…EPSS 82%analysed7.5CVE-2005-2079Symantec veritas backup exec vulnerabilityHeap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to exec…EPSS 5.2%7.5CVE-2005-2080Symantec veritas backup exec vulnerabilityUnknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 fo…EPSS 1.5%7.5CVE-2005-2051Symantec veritas backup exec vulnerabilityBuffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbi…EPSS 3.2%7.5CVE-2005-0773VERITAS Backup Exec Remote Agent stack buffer overflow via CONNECT_CLIENT_AUTHVERITAS Backup Exec Remote Agent (9.0 through 10.0 on Windows, 9.0.4019 through 9.1.307 on NetWare) has a stack-based buffer overflow triggered by a …EPSS 86%analysed6.5CVE-2006-4128Symantec veritas backup exec vulnerabilityMultiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Bac…EPSS 5.8%

Source: NIST National Vulnerability Database (record CVE-2005-2611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.