The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.
2006-12-14T20:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | symantec | veritas_netbackup_client | 5.0 | Yes |
Application | symantec | veritas_netbackup_client | 5.1 | Yes |
Application | symantec | veritas_netbackup_client | 6.0 | Yes |
Application | symantec | veritas_netbackup_enterprise_server | 5.0 | Yes |
Application | symantec | veritas_netbackup_enterprise_server | 5.1 | Yes |
Application | symantec | veritas_netbackup_enterprise_server | 6.0 | Yes |
Application | symantec | veritas_netbackup_server | 5.0 | Yes |
Application | symantec | veritas_netbackup_server | 5.1 | Yes |
Application | symantec | veritas_netbackup_server | 6.0 | Yes |