CVE-2023-37237

MEDIUM

Veritas NetBackup Appliance < 4.1.0.1 - Authenticated Command Execution via SSH

Title source: llm
STIX 2.1

Description

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0052
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
veritas/netbackup_appliance 4.1.0.1 maintenance_release1 (2 CPE variants)
veritas/netbackup_appliance < 4.1.0.1
Published Jun 29, 2023
Tracked Since Feb 18, 2026