PT-2022-26361 · Veritas · Veritas Netbackup

Published

2022-10-03

·

Updated

2022-10-04

·

CVE-2022-42306

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions prior to 8.3
Description An issue was discovered that allows an attacker with local access to send a crafted packet to pbx exchange during registration, causing a NULL pointer exception and effectively crashing the pbx exchange process.
Recommendations For versions prior to 8.3, update to version 8.3 or later to resolve the issue. As a temporary workaround, consider restricting local access to prevent potential exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2022-42306

Affected Products

Veritas Netbackup