PT-2017-18586 · Veritas · Veritas Netbackup Appliance+1

Published

2017-05-09

·

Updated

2019-10-03

·

CVE-2017-8856

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions 8.0 and earlier Veritas NetBackup Appliance versions 3.0 and earlier
Description The issue allows for unauthenticated, arbitrary remote command execution. This is achieved through the 'bprd' process.
Recommendations For Veritas NetBackup versions 8.0 and earlier, consider disabling the 'bprd' process as a temporary workaround until a patch is available. For Veritas NetBackup Appliance versions 3.0 and earlier, restrict access to the 'bprd' process to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8856

Affected Products

Veritas Netbackup
Veritas Netbackup Appliance