ZeroHour

CVE-2024-28222

CVSS 3.1
9.8 critical
EPSS
<1%p60
Published
()
Modified
Description

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.

Vendors
veritas
Products
netbackup, netbackup appliance
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.