August 15, 2005 5:50 PM PDT

Another flaw hits Veritas backup tools

A security vulnerability in Veritas backup products could put corporate networks at risk of cyberattack.

By exploiting the flaw, an attacker could get remote access and download arbitrary files, the software maker said in an advisory released on Friday. Symantec last month closed its acquisition of Veritas.

The flaw is due to a design error, the French Security Incident Response Team said in an alert. A component of the software can be accessed via a static password, according to FrSIRT, which rates the issue as "critical." An exploit for the flaw is available on the Internet, and that could aid attackers.

Affected are the backup servers for Veritas Backup Exec, media servers running the Veritas NetWare Media Server Option, and the system running the remote agents for Windows, Unix and Linux servers, Symantec said. The Remote Agent is used to trigger backup of data.

Symantec urges users of the affected products to apply the available fixes. As a temporary work-around, the vendor advises blocking external access to TCP port 10000, which is used by the flawed component.

This is the second serious security issue that has affected Veritas products in recent months. Data backup tools have become easy targets for attackers, the SANS Institute said in its most recent quarterly security update. Serious security vulnerabilities have also been disclosed in products from Computer Associates.

 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (0.84%) 0.15 17.93
Dow Jones Industrials (0.57%) 72.81 12,874.04
S&P 500 (0.68%) 9.13 1,351.77
NASDAQ (0.95%) 27.51 2,931.39
CNET TECH (0.84%) 17.13 2,049.14
  Symbol Lookup