CVE-2022-26778: Medium severity veritas system recovery vulnerability
Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configuration of the backup configuration. This could allow a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26778?
CVE-2022-26778 is a vulnerability in Veritas System Recovery (VSR) 18 and 21 that allows a user with sufficient privileges to access a network file system they are not authorized to access.
How does CVE-2022-26778 impact Veritas System Recovery?
CVE-2022-26778 impacts Veritas System Recovery (VSR) 18 and 21 by storing a network destination password in the Windows registry, potentially allowing unauthorized access to the network file system.
What is the severity of CVE-2022-26778?
The severity of CVE-2022-26778 is medium (CVSS score of 6.5).
How can I mitigate the impact of CVE-2022-26778?
To mitigate the impact of CVE-2022-26778, Veritas recommends applying the relevant security update provided by Veritas.
Where can I find more information about CVE-2022-26778?
You can find more information about CVE-2022-26778 on the Veritas website at the following link: [CVE-2022-26778](https://www.veritas.com/content/support/en_US/security/VTS21-002)