PatchSiren cyber security CVE debrief
CVE-2017-6405 Veritas CVE debrief
Veritas NetBackup 8.0 and earlier, and NetBackup Appliance 3.0 and earlier, include hostname-based security that is open to DNS spoofing. In practice, that means an attacker who can influence DNS resolution may be able to undermine hostname trust and impact integrity-sensitive security decisions. Because the issue is network reachable and requires no privileges or user interaction, it should be treated as a high-priority exposure wherever these products are still in use.
- Vendor
- Veritas
- Product
- CVE-2017-6405
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Administrators, security teams, and platform owners running Veritas NetBackup 8.0 or earlier, or NetBackup Appliance 3.0 or earlier, especially in environments that rely on hostname-based trust, authorization, or management workflows.
Technical summary
NVD maps CVE-2017-6405 to CWE-290 (Authentication Bypass by Spoofing) and assigns CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The affected product scope in the record covers Veritas NetBackup up to 8.0 and NetBackup Appliance up to 3.0. The core issue is that hostname-based security can be fooled if DNS responses are spoofed, creating a path to integrity compromise without requiring local access or user interaction.
Defensive priority
High
Recommended defensive actions
- Inventory all Veritas NetBackup and NetBackup Appliance instances and confirm whether any are at or below the affected versions.
- Follow the remediation guidance in the Veritas security advisory referenced by NVD (VTS17-003, Issue 7).
- Review any controls that treat hostname resolution as a security boundary or authentication signal.
- Strengthen DNS integrity monitoring and alert on unexpected changes affecting NetBackup-related hostnames.
- Prefer stronger identity validation than hostname-only trust where the product or deployment supports it.
Evidence notes
The supplied NVD record states that the issue affects Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, with CWE-290 and CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The CVE publication date is 2017-03-02. The 2026-05-13 modified date is record metadata and should not be interpreted as the original disclosure date.
Official resources
-
CVE-2017-6405 CVE record
CVE.org
-
CVE-2017-6405 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
Publicly disclosed in the CVE/NVD record on 2017-03-02. The later 2026-05-13 modification reflects record updates, not the original vulnerability date.