CVE-2023-38404

HIGH

Veritas InfoScale Ops Mgr <8.0.0.410 - Command Injection

Title source: llm
STIX 2.1

Description

The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
veritas/infoscale_operations_manager 7.0.0 - 8.0.0.410
Published Jul 17, 2023
Tracked Since Feb 18, 2026