CVE-2005-3658

Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).

Published: 2005-12-31 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2005-3658 is rated Moderate Risk (61.5/100): CVSS High severity, with high exploitation likelihood (EPSS 5.17%, 91th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2005-3658

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 5.67% 5.17% -0.51%
2 2025-03-30 4.21% 5.67% +1.46%
3 2025-03-29 4.21%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2005-3658

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2005-3658

Affected software / configurations for CVE-2005-3658

Vendor Product Version Raw CPE
emc legato_networker 7.1.1 cpe:2.3:a:emc:legato_networker:7.1.1:*:*:*:*:*:*:*
emc legato_networker 7.1.2 cpe:2.3:a:emc:legato_networker:7.1.2:*:*:*:*:*:*:*
emc legato_networker 7.1.3 cpe:2.3:a:emc:legato_networker:7.1.3:*:*:*:*:*:*:*
emc legato_networker 7.2 cpe:2.3:a:emc:legato_networker:7.2:*:*:*:*:*:*:*
emc legato_networker 7.2.1 cpe:2.3:a:emc:legato_networker:7.2.1:*:*:*:*:*:*:*
emc legato_networker 7.2_build172 cpe:2.3:a:emc:legato_networker:7.2_build172:*:*:*:*:*:*:*

References for CVE-2005-3658

URL Tags
ftp://ftp.legato.com/pub/NetWorker/Updates/LGTpa83990/README.TXT
http://secunia.com/advisories/18495 Patch Vendor Advisory
http://secunia.com/advisories/18615 Patch Vendor Advisory
http://securitytracker.com/id?1015500 Patch
http://securitytracker.com/id?1015545 Patch
http://sunsolve.sun.com/searchproxy/document.do?assetkey=1-26-102148-1
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=373 Patch Vendor Advisory
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=374 Patch Vendor Advisory
http://www.legato.com/support/websupport/product_alerts/011606_NW.htm
http://www.securityfocus.com/bid/16275 Patch
http://www.vupen.com/english/advisories/2006/0233 Vendor Advisory
http://www.vupen.com/english/advisories/2006/0343 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24174
https://exchange.xforce.ibmcloud.com/vulnerabilities/24175
cvelogic Threat Intelligence