← Vulnerability feed

Vulnerability record · CVE-2005-2715 · published 12 October 2005

CVE-2005-2715: VERITAS NetBackup bpjava-msvc daemon format string RCE

SSymantec Veritas · Netbackup Data And Business Center

The bpjava-msvc daemon in VERITAS NetBackup Data and Business Center 4.5FP/4.5MP and NetBackup Enterprise/Server/Client 5.0, 5.1 and 6.0 contains a format string vulnerability reachable through the COMMAND_LOGON_TO_MSERVER command. A remote, unauthenticated attacker can supply crafted format specifiers that corrupt memory and execute arbitrary code on the backup server.

10.0 CVSS 2.0 High EPSS 60% · top 0.9%
10.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and full confidentiality, integrity and availability impact, plus public exploit references and very high EPSS.

What it is

The bpjava-msvc daemon in VERITAS NetBackup Data and Business Center 4.5FP/4.5MP and NetBackup Enterprise/Server/Client 5.0, 5.1 and 6.0 contains a format string vulnerability reachable through the COMMAND_LOGON_TO_MSERVER command. A remote, unauthenticated attacker can supply crafted format specifiers that corrupt memory and execute arbitrary code on the backup server.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the bpjava-msvc service, typically root or SYSTEM on the backup host. That host holds backup credentials and data for the whole environment, so compromise can cascade to managed clients.

Attack surface

Reachable over the network via the Java user interface service port; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The attacker only needs to send a crafted COMMAND_LOGON_TO_MSERVER request to the daemon.

Exploitation

Not listed in CISA KEV, but EPSS is 0.60356 (99.1st percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Apply the vendor patches referenced in the Symantec, VERITAS and Sun advisories for the affected NetBackup versions.
  • Restrict network access to the bpjava-msvc service port to trusted management hosts using firewall rules or host-based ACLs.
  • Disable or stop the bpjava-msvc daemon on hosts that do not require the Java user interface service.
  • Segment backup servers from general user and internet-facing networks to limit reachable attack paths.
  • Monitor vendor advisories for the affected 4.5/5.x/6.0 branches, which are long past end of support.

Detection

  • Inspect bpjava-msvc service logs for malformed or unexpected COMMAND_LOGON_TO_MSERVER requests and format-specifier characters in command arguments.
  • Alert on unexpected child processes or shell spawns originating from the bpjava-msvc daemon process.
  • Monitor network traffic to the bpjava-msvc port for connections from hosts outside the approved backup management range.
  • Baseline and watch for crashes or restarts of the bpjava-msvc service, which can accompany format string exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2715 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2005-2715), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.