Initial Publication Date: Advisory Status: Advisory Severity: Legacy ID
16 Aug 2006 Closed Medium
SYM06-015
Summary
Symantec discovered a security issue in Symantec's Veritas NetBackup 6.0 PureDisk Remote Office Edition. An unauthorized user with access to the network and the server hosting the management interface can potentially bypass the management interface authentication to gain access and elevate their privileges on the system
Severity Medium (highly dependent on network configuration)
Note: For systems running NetBackup 6.0 GA PureDisk Remote Office Edition it will be necessary to install Maintenance Pack 1 (NB_PDE_60_MP1_283808) prior to applying this Security Pack (NB_PDE_60_MP1_P01). This issue ONLY affects the product and versions listed above.
Issues
Details
An internal review revealed a potential elevation of privilege issue in the Symantec Veritas NetBackup PureDisk management interface. The management interface is accessible only through an SSL web connection by default. However it is possible for a non-privileged user with access to the network and the server hosting the Symantec Veritas NetBackup PureDisk management interface, to bypass the management interface authentication and further leverage their access to elevate privileged access on the server.
A CVE Candidate name is being requested from the Common Vulnerabilities and Exposures (CVE) initiative for this issue. This advisory will be revised accordingly upon receipt of the CVE Candidate name. This issue is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.
Mitigation
Symantec Response
Symantec engineers have addressed the issues identified above and made Security updates available.
Symantec strongly recommends all customers apply the latest security update to protect against threats of this nature.
Symantec knows of no exploitation of or adverse customer impact from these issues.
The patches listed above for affected products are available through the following location: http://support.veritas.com/docs/284734 for Symantec Veritas NetBackup PureDisk Remote Office Edition.
Best Practices
As part of normal best practices, Symantec recommends:
Restrict access to administration or management systems to authorized privileged users only
Block remote access to all ports not essential for efficient operation
Restrict remote access, if required, to trusted/authorized systems only
Remove/disable unnecessary accounts or restrict access according to security policy as required
Run under the principle of least privilege where possible
Keep all operating systems and applications updated with the latest vendor patches
Follow a multi-layered approach to security. Run both firewall and antivirus applications, at a minimum, to provide multiple points of detection and protection to both inbound and outbound threats
Deploy network intrusion detection systems to monitor network traffic for signs of anomalous or suspicious activity. This may aid in detection of attacks or malicious activity related to exploitation of latest vulnerabilities
Legacy ID
SYM06-015
Terms of use for this information are found in Legal Notices.
Translated Content
This is machine translated content
Login to Subscribe
Please login to set up your
subscription.
Would you like to be subscribed to future notifications for this article?
For security reasons, your link to this document has expired. Please click on the attachment link to access this file.
The attachment that you are looking for no longer exists.
There has been an issue retrieving your attachment. Please try again.