|
Legato NetWorker contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the AUTH_UNIX authentication mechanism used for RPC services allows username spoofing by remote users in the nwadmin, nsradmin, and nsrports programs, or UID spoofing in the recover and nsrexecd programs. This flaw may allow a remote attacker to execute arbitrary commands on a NetWorker client system, modify the NetWorker server configuration, and view backed up files from any system, leading to a loss of confidentiality, integrity and availability.
|