cancel
Showing results for 
Search instead for 
Did you mean: 

Upgrade Veritas Remote Agent 10.0.5484 to Symantec 12.5 rev 2213

jnguyen09
Level 2

Hi, need help to patches the Remote Agent  after a security hole, somehow never have this patches install.

 

https://support.symantec.com/content/unifiedweb/en_US/article.SYMSA1166.html

http://securityresponse.symantec.com/avcenter/security/Content/2008.11.19.html

I need this patch for version 12.5 rev 2213, when I click on it, it no longer available.  Can any help lending me the file or the hotfixes.  Or is there a other way to get this fixes?  Or do we have a higher version of Remote agent 12.5 rev 2213 that already have that patch apply?  thanks.

 

 

 

5 REPLIES 5

Colin_Weaver
Moderator
Moderator
Employee Accredited Certified

If your company has concerns about security vulnerabilities then to be honest you need to get onto a much newer version of Backup Exe than 12.x - just thinking of a major one, 12.5 is well before we fixed the "Man in the Midddle" vulnerability by introducing TLS between agent and Backup Exec server in 2010 R3 ( https://support.symantec.com/en_US/article.SYMSA1223.html ) .  There have been 7 major Backup Exec releases since Backup Exec 12.5 (which is why the patch downloads are no longer available for those older versions.) - 12.5 has been out of support since Februray 2015 and I suspect we stopped providing vulnerability patches for 12.5 well before that timeframe as engineering level support for it was almost certainly dropped by August 2012.

With regards the 12.5 download, it could not actually be used with a 10.x server, so I hope you were not still on 10.0.5484 on your server and thinking to upgrade the agent before the server is on a newer version.

Also that specific patch could have originally been made unavailable if it was included in a later Service Pack, and judging by the answer in this post it would have been around the time of Service Pack 1:

https://vox.veritas.com/t5/Backup-Exec/Vulnerability-CVE-2005-2611-found-by-Foundstone-in-client-12-...

As 12.5 got to Service Pack 4, you may already have the correct patch within a service pack - so assuming you do have 12.5 on your server, what Service Pack do you have installed and if it is greater than SP1 then it would appear that all you need to do is push install the agent from the server to the remote system.

If you do consider moving to the latest version (20.3) , advice and info (best practices etc) is available here:

https://www.veritas.com/content/support/en_US/article.100044372.html

 

 

 

 

 

 

 

 

 

 

 

 

 

 

I have check our version of BE, and it has SP4 installed, and Hotfix 358478.  I have pushed the agent again to the ONE clien to test it out, and the security scan still pickup the security hole mention above on the two links.  Is there a documentation stating SP4 fixes Hotfix 314380 for 12.5

I have not yet remove the agent, and push it again..Can't upgrade BE version right now since hardware and software limitation.

You guy doesn't have that hotfixes store in an archive somewhere?

 

Colin_Weaver
Moderator
Moderator
Employee Accredited Certified

Hotfix 314380 would definitely have been included in all the later Service packs for BE 12.5 and in fact no point in us re-issuing the hotfix installation file (even if we could) as it will not install over Service Pack 4 anyway

If your vulnerability checker is still showing a problem, then you will need to get onto a newer BE version (unless it is warning you about the vulnerability but not able to validate that you already have the fix)

 

 

Ok, Thanks

I have remove the Remote Agents, and repushed again from BE 12.5 rev 2213 with SP4 update.  And will has to have it scan again to see if that would pass the vuneribility test...  If not, what option do we have?

Yes, we are NOT using Remote Agent 10.0.5484 (autofill fill that in, I wasnt aware).  Do we have a higher version of 10.0.5484 that would work with BE 12.5 rev 2213?

Colin_Weaver
Moderator
Moderator
Employee Accredited Certified

OK so I think you need some product history

10.0.5484 is the first version of Backup Exec 10D and was released in 2005

12.5.2213 is Backup Exec 12.5 and was released in 2008 but is actually the 6th version after 10.0.5484 (hence the agents for 10D might work with 12.5 but are really old and should not be used with 12.5 (12.5 agents will not work at all with 10.0.5484 as while we do offer backward compatibility that would count as forward compatibility ). If you do not have 10.0 in your environment and this was a mistake in your initial post then anythign to do with an even older version is not an option.

After 12.5 we released three 2010 versions, 2012, 2014 , 15, 16 and 20.x. Which means not only is 12.5 itself 10 years old but it has also been replaced by 8 newer versions (and that count does not include service packs)  as such not only do we no longer support 12.5 but discontinued developing patches for it some time ago.  If you already have SP4 installed on 12.5 then there is no further update and nothing you can achieve with that version and you will need a newer version fo Backup Exec (which will have a cost)

As I previously stated - if you have concerns about security vulnerabilities then in no way does 12.5 have updates for anything recent, so really your best option is invest in newer software. Unfortunately the latest Backup Exec versions do not support older operating system or applications (anything 32bit for starters) but then anything too old for Backup Exec to support probably also has a huge number of potential security vulnerabilities as such you may be need to invest in more than just a an update to the backup software (and should carefully check compatibility lists )

 

As this current time I doubt you have any options that do not have a significant cost to them (but then how much is you data worth if you lost it all.)