CVE-2024-35204: High severity Veritas System Recovery vulnerability
Published May 13, 2024
·Updated
Veritas System Recovery before 23.3Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.
Affected Software
1 affected component
Veritas System Recovery<23.3_Hotfix
Event History
May 13, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35204?
CVE-2024-35204 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-35204?
To fix CVE-2024-35204, you should upgrade to Veritas System Recovery version 23.3_Hotfix or later.
3
Which versions are affected by CVE-2024-35204?
CVE-2024-35204 affects all versions of Veritas System Recovery prior to 23.3_Hotfix.
4
What type of attack does CVE-2024-35204 allow?
CVE-2024-35204 allows low-privileged users to conduct unauthorized access or modifications due to incorrect folder permissions.
5
Who is affected by CVE-2024-35204?
Users of Veritas System Recovery versions prior to 23.3_Hotfix may be affected by CVE-2024-35204.