ZDI-CAN-24344: ZDI-24-1665: Veritas Enterprise Vault Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Veritas Enterprise Vault. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2024-53914.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-24344?
ZDI-CAN-24344 has a CVSS rating of 8.0, indicating a high severity level.
How do I fix ZDI-CAN-24344?
To fix ZDI-CAN-24344, upgrade your Veritas Enterprise Vault to the latest patched version provided by Veritas.
Who is affected by ZDI-CAN-24344?
ZDI-CAN-24344 affects installations of Veritas Enterprise Vault that are accessible to network-adjacent attackers.
Is authentication required to exploit ZDI-CAN-24344?
Yes, authentication is required to exploit the ZDI-CAN-24344 vulnerability.
What type of vulnerability is ZDI-CAN-24344?
ZDI-CAN-24344 is a code execution vulnerability that allows attackers to execute arbitrary code on affected systems.