ZDI-CAN-24343: ZDI-24-1666: Veritas Enterprise Vault Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Veritas Enterprise Vault. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2024-53913.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24343?
ZDI-CAN-24343 has been assigned a CVSS rating of 8.0, indicating a high severity level.
How do I fix ZDI-CAN-24343?
To fix ZDI-CAN-24343, update your Veritas Enterprise Vault installation to the latest patched version provided by the vendor.
Who can exploit the ZDI-CAN-24343 vulnerability?
ZDI-CAN-24343 can be exploited by authenticated, network-adjacent attackers.
What type of attacks can be executed using ZDI-CAN-24343?
ZDI-CAN-24343 allows attackers to execute arbitrary code on affected installations of Veritas Enterprise Vault.
What is the affected software version for ZDI-CAN-24343?
ZDI-CAN-24343 affects installations of Veritas Enterprise Vault that have not been updated with the latest security patches.