First published: Wed Mar 09 2022(Updated: )
Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas System Recovery | =18.0 | |
Veritas System Recovery | =21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26778 is a vulnerability in Veritas System Recovery (VSR) 18 and 21 that allows a user with sufficient privileges to access a network file system they are not authorized to access.
CVE-2022-26778 impacts Veritas System Recovery (VSR) 18 and 21 by storing a network destination password in the Windows registry, potentially allowing unauthorized access to the network file system.
The severity of CVE-2022-26778 is medium (CVSS score of 6.5).
To mitigate the impact of CVE-2022-26778, Veritas recommends applying the relevant security update provided by Veritas.
You can find more information about CVE-2022-26778 on the Veritas website at the following link: [CVE-2022-26778](https://www.veritas.com/content/support/en_US/security/VTS21-002)