CVE-2023-37237

MEDIUM

Veritas Netbackup Appliance - Incorrect Permission Assignment

Title source: rule
STIX 2.1

Description

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
veritas/netbackup_appliance 4.1.0.1 maintenance_release1 (2 CPE variants)
veritas/netbackup_appliance < 4.1.0.1
Published Jun 29, 2023
Tracked Since Feb 18, 2026