First published: Thu Mar 02 2017(Updated: )
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Access Appliance | <=7.2.1 | |
Veritas NetBackup | <=7.7.1 | |
Veritas NetBackup Appliance | <=2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6406 is rated as a critical vulnerability due to its potential for arbitrary privileged command execution.
To fix CVE-2017-6406, upgrade to Veritas NetBackup version 7.7.2 or later, and Veritas NetBackup Appliance version 2.7.2 or later.
CVE-2017-6406 affects Veritas NetBackup versions prior to 7.7.2, NetBackup Appliance versions before 2.7.2, and Veritas Access Appliance versions before 7.2.1.
CVE-2017-6406 facilitates an attack through arbitrary privileged command execution via directory traversal using "../" substrings.
Yes, CVE-2017-6406 can be exploited remotely if the affected software is improperly configured.