First published: Thu Mar 07 2024(Updated: )
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas NetBackup | <8.1.2 | |
Veritas NetBackup Appliance Firmware | <3.1.2 | |
Veritas NetBackup | <8.1.2 | |
Veritas NetBackup Appliance Firmware | <3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28222 is considered a high-severity vulnerability due to the potential for unauthenticated file uploads and execution.
To fix CVE-2024-28222, users should upgrade to Veritas NetBackup version 8.1.2 or later, and NetBackup Appliance version 3.1.2 or later.
CVE-2024-28222 affects Veritas NetBackup versions prior to 8.1.2 and Veritas NetBackup Appliance versions prior to 3.1.2.
Any organization using the vulnerable versions of Veritas NetBackup or NetBackup Appliance could potentially be affected by CVE-2024-28222.
The impact of CVE-2024-28222 includes the ability for an unauthenticated attacker to upload and execute arbitrary files on the affected systems.