CVE-2022-42306: Null Pointer Dereference
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can send a crafted packet to pbxexchange during registration and cause a NULL pointer exception, effectively crashing the pbxexchange process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42306?
CVE-2022-42306 is a vulnerability discovered in Veritas NetBackup through 8.2 and related Veritas products.
What is the severity of CVE-2022-42306?
The severity of CVE-2022-42306 is medium with a severity value of 5.5.
How does CVE-2022-42306 affect Veritas NetBackup?
CVE-2022-42306 affects Veritas NetBackup version up to and including 8.2.
How can an attacker exploit CVE-2022-42306?
An attacker with local access can send a crafted packet to pbx_exchange during registration, causing a NULL pointer exception and crashing the pbx_exchange process.
Is there a fix for CVE-2022-42306?
Currently, there is no known fix for CVE-2022-42306. It is recommended to follow the guidance provided by Veritas.