PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6405 Veritas CVE debrief

Veritas NetBackup 8.0 and earlier, and NetBackup Appliance 3.0 and earlier, include hostname-based security that is open to DNS spoofing. In practice, that means an attacker who can influence DNS resolution may be able to undermine hostname trust and impact integrity-sensitive security decisions. Because the issue is network reachable and requires no privileges or user interaction, it should be treated as a high-priority exposure wherever these products are still in use.

Vendor
Veritas
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-02
Original CVE updated
2026-05-13
Advisory published
2017-03-02
Advisory updated
2026-05-13

Who should care

Administrators, security teams, and platform owners running Veritas NetBackup 8.0 or earlier, or NetBackup Appliance 3.0 or earlier, especially in environments that rely on hostname-based trust, authorization, or management workflows.

Technical summary

NVD maps CVE-2017-6405 to CWE-290 (Authentication Bypass by Spoofing) and assigns CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The affected product scope in the record covers Veritas NetBackup up to 8.0 and NetBackup Appliance up to 3.0. The core issue is that hostname-based security can be fooled if DNS responses are spoofed, creating a path to integrity compromise without requiring local access or user interaction.

Defensive priority

High

Recommended defensive actions

  • Inventory all Veritas NetBackup and NetBackup Appliance instances and confirm whether any are at or below the affected versions.
  • Follow the remediation guidance in the Veritas security advisory referenced by NVD (VTS17-003, Issue 7).
  • Review any controls that treat hostname resolution as a security boundary or authentication signal.
  • Strengthen DNS integrity monitoring and alert on unexpected changes affecting NetBackup-related hostnames.
  • Prefer stronger identity validation than hostname-only trust where the product or deployment supports it.

Evidence notes

The supplied NVD record states that the issue affects Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, with CWE-290 and CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N. The CVE publication date is 2017-03-02. The 2026-05-13 modified date is record metadata and should not be interpreted as the original disclosure date.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6405 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6405

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6405 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6405

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.