Vulnerabilities > CVE-2017-6406 - Unspecified vulnerability in Veritas Netbackup and Netbackup Appliance

047910
CVSS 8.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
veritas
nessus

Summary

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.

Nessus

NASL familyCGI abuses
NASL idVERITAS_NETBACKUP_APPLIANCE_VTS17-003.NASL
descriptionAccording to its self-reported version, the remote Veritas NetBackup Appliance is 2.7.x or 3.0.x. It is, therefore, affected by multiple vulnerabilities.
last seen2020-06-01
modified2020-06-02
plugin id104888
published2017-11-30
reporterThis script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/104888
titleVeritas NetBackup Appliance < 2.7.2 / 3.1.0 Multiple Vulnerabilities (VTS17-003)