In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veritas
Veritas netbackup Veritas netbackup Appliance |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:veritas:netbackup:*:*:*:*:*:*:*:* cpe:2.3:a:veritas:netbackup_appliance:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Veritas
Veritas netbackup Veritas netbackup Appliance |
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-07T00:00:00
Updated: 2024-11-15T19:13:08.179Z
Reserved: 2024-03-07T00:00:00
Link: CVE-2024-28222
Updated: 2024-08-02T00:48:49.473Z
Status : Analyzed
Published: 2024-03-07T07:15:08.377
Modified: 2025-01-21T18:29:18.877
Link: CVE-2024-28222
No data.