PT-2022-27863 · Veritas · Veritas Netbackup Access Appliance+1

Published

2022-12-04

·

Updated

2022-12-06

·

CVE-2022-46414

CVSS v3.1

9.8

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Veritas NetBackup Flex Scale versions 1.0 through 3.0 Veritas NetBackup Access Appliance versions 8.0.0 through 8.0.100
Description An issue was discovered that allows unauthenticated remote command execution via the management portal.
Recommendations For Veritas NetBackup Flex Scale versions 1.0 through 3.0, update to a version later than 3.0 to resolve the issue. For Veritas NetBackup Access Appliance versions 8.0.0 through 8.0.100, update to a version later than 8.0.100 to resolve the issue.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-46414

Affected Products

Veritas Netbackup Access Appliance
Veritas Netbackup Flex Scale