PT-2024-2014 · Veritas · Veritas Netbackup+1

Published

2024-03-07

·

Updated

2025-01-21

·

CVE-2024-28222

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions prior to 8.1.2 Veritas NetBackup Appliance versions prior to 3.1.2
Description The issue is related to inadequate validation of the file path by the BPCD process, allowing an unauthenticated attacker to upload and execute a custom file. This could enable remote execution of malicious code on NetBackup servers and clients.
Recommendations For Veritas NetBackup versions prior to 8.1.2, update to version 8.1.2 or later. For Veritas NetBackup Appliance versions prior to 3.1.2, update to version 3.1.2 or later. As a temporary workaround, consider restricting access to the BPCD process to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-01877
CVE-2024-28222

Affected Products

Veritas Netbackup
Veritas Netbackup Appliance