Vulnerability record · CVE-2005-2611 · published 17 August 2005
CVE-2005-2611: VERITAS Backup Exec and NetBackup NDMP agent static password flaw
SSymantec Veritas · Backup Exec
The NDMP agent in VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 authenticates to the backup server using a static password. Because the credential is fixed and shared, anyone who can reach the NDMP service can impersonate the agent and gain the backup server's file access.
Description
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the backup server.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network access yielding complete confidentiality and integrity impact, with high EPSS and public exploit references.
What it is
The NDMP agent in VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 authenticates to the backup server using a static password. Because the credential is fixed and shared, anyone who can reach the NDMP service can impersonate the agent and gain the backup server's file access.
Impact
An attacker gains read and write access to arbitrary files through the backup server, effectively full control over backed-up data and potentially the server itself.
Attack surface
Reachable over the network via the NDMP agent-to-server authentication path; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.87026 (99.7th percentile) and multiple references carry an Exploit tag, indicating public exploit material exists.
What to do
- Apply the vendor patches referenced in the Symantec and Secunia advisories.
- Restrict network access to NDMP agent and backup server ports to trusted management hosts only.
- Replace the static NDMP credential with a unique, rotated secret where the product version allows it.
- Segment backup infrastructure from general user and internet-reachable networks.
- Monitor vendor advisories for end-of-life status and migrate off unsupported versions.
Detection
- Alert on NDMP connections to backup servers from hosts outside the known agent inventory.
- Baseline and monitor file read/write activity on backup servers for unexpected access patterns.
- Review backup server logs for authentication from unexpected source addresses or repeated agent logins.
- Hunt for NDMP traffic on non-standard or externally facing interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2611 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.