First published: Fri Sep 23 2022(Updated: )
Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas System Recovery | >=18.0<18.0.4.57090 | |
Veritas System Recovery | >=21<21.0.3.62140 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41320 is a vulnerability in Veritas System Recovery (VSR) versions 18 and 21 where a network destination password is stored in the Windows registry, potentially allowing unauthorized access to a network file system.
Veritas System Recovery (VSR) versions 18 and 21 are affected by CVE-2022-41320.
CVE-2022-41320 has a severity rating of 6.5, which is classified as medium.
The vulnerability can be exploited by a Windows user with sufficient privileges to access a network file system.
Veritas has released a security advisory with recommended actions to address CVE-2022-41320. Please refer to the official Veritas support page for more information.