CVE-2017-6406: High severity Veritas Access vulnerability
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6406?
CVE-2017-6406 is rated as a critical vulnerability due to its potential for arbitrary privileged command execution.
How do I fix CVE-2017-6406?
To fix CVE-2017-6406, upgrade to Veritas NetBackup version 7.7.2 or later, and Veritas NetBackup Appliance version 2.7.2 or later.
What software versions are affected by CVE-2017-6406?
CVE-2017-6406 affects Veritas NetBackup versions prior to 7.7.2, NetBackup Appliance versions before 2.7.2, and Veritas Access Appliance versions before 7.2.1.
What type of attack does CVE-2017-6406 facilitate?
CVE-2017-6406 facilitates an attack through arbitrary privileged command execution via directory traversal using "../" substrings.
Is CVE-2017-6406 exploitable remotely?
Yes, CVE-2017-6406 can be exploited remotely if the affected software is improperly configured.