Vulnerabilities > CVE-2017-6406 - Unspecified vulnerability in Veritas Netbackup and Netbackup Appliance
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | VERITAS_NETBACKUP_APPLIANCE_VTS17-003.NASL |
description | According to its self-reported version, the remote Veritas NetBackup Appliance is 2.7.x or 3.0.x. It is, therefore, affected by multiple vulnerabilities. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 104888 |
published | 2017-11-30 |
reporter | This script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/104888 |
title | Veritas NetBackup Appliance < 2.7.2 / 3.1.0 Multiple Vulnerabilities (VTS17-003) |