QID 379616

QID 379616: Veritas NetBackup Snapshot Manager Improper Certificate Validation Vulnerability

A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service.

Affected Versions
Veritas NetBackup Snapshot Manager Versions 8.3.0.1, 8.3.0.2, 9.0, 9.1, 9.1.0.1, 10.0, 10.0.0.1, 10.1, 10.1.1, 10.2. Earlier unsupported versions of the predecessor Veritas NetBackup

QID Detection Logic (Authenticated):
This qid checks Netbackup version on /usr/openv/netbackup/version

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to VTS23-011 to address this issue and obtain more information.

    CVEs related to QID 379616

    Software Advisories
    Advisory ID Software Component Link
    VTS23-011 Unix URL Logo www.veritas.com/support/en_US/security/VTS23-011