PT-2019-13686 · Veritas · Veritas Resiliency Platform

Published

2019-07-29

·

Updated

2020-08-24

·

CVE-2019-14417

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Veritas Resiliency Platform versions prior to 3.4 HF1
Description An issue in the DNS functionality of the software allows a malicious user to execute arbitrary commands with root privilege within the virtual machine.
Recommendations For versions prior to 3.4 HF1, update to version 3.4 HF1 or later to resolve the issue. As a temporary workaround, consider restricting access to the DNS functionality to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-14417

Affected Products

Veritas Resiliency Platform