Command Injection Vulnerability in Symantec Veritas NetBackup
CVE-2006-4902
Currently unrated
Key Information:
- Vendor
Symantec
- Vendor
- CVE Published:
- 14 December 2006
What is CVE-2006-4902?
The bpcd daemon in Symantec's Veritas NetBackup is susceptible to a command injection flaw due to inadequate validation of chained commands. This vulnerability enables remote attackers to execute arbitrary commands by appending malicious instructions to legitimate commands. The affected versions include NetBackup 5.0 prior to MP7, 5.1 prior to MP6, and 6.0 prior to MP4. Users are advised to upgrade to the latest patched versions to mitigate this significant risk.