EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
総合評価: CVE-2005-0357 は中リスク(56.6/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 4.50%、90 パーセンタイル) 根拠: EPSS 上、短期間での悪用可能性は高い水準です。 推奨対応: 悪用可能性が高いため、影響範囲の確認と修補の優先付けを推奨します。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 17.71% | 4.50% | -13.22% |
| 2 | 2025-03-30 | 15.50% | 17.71% | +2.21% |
| 3 | 2025-03-29 | — | 15.50% | — |
EPSS の全履歴 (全 11 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| emc | legato_networker | 4.2.2 | cpe:2.3:a:emc:legato_networker:4.2.2:*:*:*:*:*:*:* |
| emc | legato_networker | 6.0 | cpe:2.3:a:emc:legato_networker:6.0:*:*:*:*:*:*:* |
| emc | legato_networker | 6.1 | cpe:2.3:a:emc:legato_networker:6.1:*:*:*:*:*:*:* |
| emc | legato_networker | 7.2 | cpe:2.3:a:emc:legato_networker:7.2:*:*:*:*:*:*:* |
| emc | legato_networker | 7.13 | cpe:2.3:a:emc:legato_networker:7.13:*:*:*:*:*:*:* |
| sun | solstice_backup | 6.0 | cpe:2.3:a:sun:solstice_backup:6.0:*:*:*:*:*:*:* |
| sun | solstice_backup | 6.1 | cpe:2.3:a:sun:solstice_backup:6.1:*:*:*:*:*:*:* |
| sun | storedge_enterprise_backup_software | 7.0 | cpe:2.3:a:sun:storedge_enterprise_backup_software:7.0:*:*:*:*:*:*:* |
| sun | storedge_enterprise_backup_software | 7.1 | cpe:2.3:a:sun:storedge_enterprise_backup_software:7.1:*:*:*:*:*:*:* |
| sun | storedge_enterprise_backup_software | 7.2 | cpe:2.3:a:sun:storedge_enterprise_backup_software:7.2:*:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| http://secunia.com/advisories/16464 | Patch Vendor Advisory |
| http://secunia.com/advisories/16470 | Vendor Advisory |
| http://securitytracker.com/id?1014713 | Patch |
| http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1 | Patch Vendor Advisory |
| http://www.kb.cert.org/vuls/id/606857 | Patch Third Party Advisory US Government Resource |
| http://www.legato.com/support/websupport/product_alerts/081605_NW_authentication.htm | Patch |
| http://www.osvdb.org/18800 | |
| http://www.securityfocus.com/bid/14582 | Patch |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/21887 |