CVE-2022-41320: Medium severity Veritas System Recovery vulnerability
Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
For VSR 18 and VSR 21, do not store the network destination password in the Windows registry; reconfigure the backup configuration so the destination credentials are not left stored there.
Veritas System Recovery (VSR) Network destination password stored in Windows registry = Remove/avoid storing the network destination password in the Windows registry - Operational
After changing the backup configuration to stop storing the network destination password in the Windows registry (VSR 18/VSR 21), review the registry for the previously stored network destination password and remediate it (e.g., clear/remove the exposed value) to reduce the chance of unauthorized access.
Event History
Frequently Asked Questions
What is CVE-2022-41320?
CVE-2022-41320 is a vulnerability in Veritas System Recovery (VSR) versions 18 and 21 where a network destination password is stored in the Windows registry, potentially allowing unauthorized access to a network file system.
Which software versions are affected by CVE-2022-41320?
Veritas System Recovery (VSR) versions 18 and 21 are affected by CVE-2022-41320.
What is the severity of CVE-2022-41320?
CVE-2022-41320 has a severity rating of 6.5, which is classified as medium.
How can CVE-2022-41320 be exploited?
The vulnerability can be exploited by a Windows user with sufficient privileges to access a network file system.
Is there a fix available for CVE-2022-41320?
Veritas has released a security advisory with recommended actions to address CVE-2022-41320. Please refer to the official Veritas support page for more information.