CVE-2022-46414
CRITICALVeritas NetBackup <3.0, Access Appliance <8.0.100 - RCE
Title source: llmDescription
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
Scores
CVSS v3
9.8
EPSS
0.0173
EPSS Percentile
82.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-306
Status
published
Affected Products (2)
veritas/access_appliance
< 8.0.100
veritas/netbackup_flex_scale_appliance
< 3.0
Timeline
Published
Dec 04, 2022
Tracked Since
Feb 18, 2026