CVE-2015-6552: Critical severity symantec netbackup appliance vulnerability
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 allows remote attackers to make arbitrary RPC calls via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6552?
CVE-2015-6552 has a medium severity rating due to its potential for remote exploitation.
How do I fix CVE-2015-6552?
To fix CVE-2015-6552, upgrade Veritas NetBackup and NetBackup Appliance to versions that are patched, such as 7.7.2 or higher for NetBackup and 2.7.2 or higher for NetBackup Appliance.
What versions of Veritas NetBackup are affected by CVE-2015-6552?
The affected versions of Veritas NetBackup include 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2.
Which versions of NetBackup Appliance are vulnerable to CVE-2015-6552?
NetBackup Appliance versions 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and 2.7.x before 2.7.2 are vulnerable.
Can CVE-2015-6552 be exploited remotely?
Yes, CVE-2015-6552 can be exploited remotely by attackers due to a vulnerability in the management-services protocol implementation.