CVE-2023-37237

MEDIUM

Veritas Netbackup Appliance - Incorrect Permission Assignment

Title source: rule

Description

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 28.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Classification

CWE
CWE-732
Status published

Affected Products (3)

veritas/netbackup_appliance < 4.1.0.1
veritas/netbackup_appliance
veritas/netbackup_appliance

Timeline

Published Jun 29, 2023
Tracked Since Feb 18, 2026