PatchSiren cyber security CVE debrief
CVE-2017-6405 Veritas CVE debrief
Veritas NetBackup 8.0 and earlier, and NetBackup Appliance 3.0 and earlier, include hostname-based security that is open to DNS spoofing. In practice, that means an attacker who can influence DNS resolution may be able to undermine hostname trust and impact integrity-sensitive security decisions. Because the issue is network reachable and requires no privileges or user interaction, it should be treated as a high-priority exposure wherever these products are still in use.
- Vendor
- Veritas
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Administrators, security teams, and platform owners running Veritas NetBackup 8.0 or earlier, or NetBackup Appliance 3.0 or earlier, especially in environments that rely on hostname-based trust, authorization, or management workflows.
Technical summary
NVD maps CVE-2017-6405 to CWE-290 (Authentication Bypass by Spoofing) and assigns CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The affected product scope in the record covers Veritas NetBackup up to 8.0 and NetBackup Appliance up to 3.0. The core issue is that hostname-based security can be fooled if DNS responses are spoofed, creating a path to integrity compromise without requiring local access or user interaction.
Defensive priority
High
Recommended defensive actions
- Inventory all Veritas NetBackup and NetBackup Appliance instances and confirm whether any are at or below the affected versions.
- Follow the remediation guidance in the Veritas security advisory referenced by NVD (VTS17-003, Issue 7).
- Review any controls that treat hostname resolution as a security boundary or authentication signal.
- Strengthen DNS integrity monitoring and alert on unexpected changes affecting NetBackup-related hostnames.
- Prefer stronger identity validation than hostname-only trust where the product or deployment supports it.
Evidence notes
The supplied NVD record states that the issue affects Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, with CWE-290 and CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The CVE publication date is 2017-03-02. The 2026-05-13 modified date is record metadata and should not be interpreted as the original disclosure date.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6405 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6405
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6405 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6405
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.veritas.com/content/support/en_US/security/VTS17-003.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.