CVE-2009-3027
Backup Exec Continuous Protection Server vulnerability
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.
Affected product
Backup Exec Continuous Protection Server
CVSS vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Risk analysis
Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no authentication. Successful exploitation leads to complete impact to confidentiality, complete impact to integrity, complete impact to availability.
Its EPSS score of 10.6% reflects a moderate probability of exploitation activity in the wild over the next 30 days, placing it above 95% of all scored CVEs.
Check your external exposure to CVE-2009-3027
- Confirm whether Symantec Backup Exec Continuous Protection Server is running on any internet-facing host or subdomain.
- Match discovered service fingerprints against the version affected by CVE-2009-3027.
- Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.
How ThreatPort helps with CVE-2009-3027
ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2009-3027 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.
Run a free external exposure scan