21.2 이전 Veritas Backup Exec에서 문제가 발견되었습니다. 클라이언트와 Agent 간 통신에는 성공적인 인증이 필요하며, 이는 일반적으로 안전한 TLS 통신을 통해 완료됩니다. 그러나 SHA Authentication 방식의 취약점으로 인해 공격자가 무단 접근 권한을 얻고 인증 절차를 완료할 수 있습니다. 이후 클라이언트는 인증된 연결에서 데이터 관리 프로토콜 명령을 실행할 수 있습니다. 공격자는 이러한 명령 중 하나를 사용하여 시스템 권한으로 시스템에서 임의의 명령을 실행할 수 있습니다.
21.2 이전 Veritas Backup Exec에서 문제가 발견되었습니다. 클라이언트와 Agent 간 통신에는 성공적인 인증이 필요하며, 이는 일반적으로 안전한 TLS 통신을 통해 완료됩니다. 그러나 SHA Authentication 방식의 취약점으로 인해 공격자가 무단 접근 권한을 얻고 인증 절차를 완료할 수 있습니다. 이후 클라이언트는 인증된 연결에서 데이터 관리 프로토콜 명령을 실행할 수 있습니다. 공격자는 이러한 명령 중 하나를 사용하여 시스템 권한으로 시스템에서 임의의 명령을 실행할 수 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. The attacker could use one of these commands to execute an arbitrary command on the system using system privileges.