QID 378530

Date Published: 2023-08-02

QID 378530: Veritas NetBackup Multiple Vulnerabilities (VTS22-004)

Veritas NetBackup is an enterprise level heterogeneous backup and recovery suite.

Affected Versions:
Veritas NetBackup 8.1.x, 8.2, 8.3.x, 9.0.x, 9.1.x

QID Detection Logic (Authenticated):
Operating Systems: Windows
The QID checks for the File Version of nbutil.exe

An attacker can perform Authenticated Conditional Remote Command Execution, Arbitrary File Write, Authenticated Remote Command Execution, Local Privilege Escalation

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has issued a fix for these vulnerabilities. Please refer to the vendor advisory VTS22-004 which addresses this issue.

    Software Advisories
    Advisory ID Software Component Link
    VTS22-004 URL Logo www.veritas.com/content/support/en_US/security/VTS22-004