CVE-2013-4677: Medium severity veritas backup exec vulnerability
Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4677?
CVE-2013-4677 is considered a medium severity vulnerability due to weak permissions allowing unauthorized access to sensitive backup data.
How do I fix CVE-2013-4677?
To fix CVE-2013-4677, apply the latest service pack updates for Backup Exec 2010 R3 and 2012 that correct the file permission issues.
Who is affected by CVE-2013-4677?
CVE-2013-4677 affects users of Symantec Backup Exec 2010 R3 versions before SP3 and Backup Exec 2012 versions before SP2.
What type of impact can CVE-2013-4677 have?
CVE-2013-4677 can lead to unauthorized data access and potential data manipulation through weak backup file permissions.
Is there a workaround for CVE-2013-4677?
While applying updates is recommended, temporarily restricting access to the backup data files can serve as a workaround until patches are applied.