Local Access Vulnerability in Veritas NetBackup and Related Products
CVE-2022-42306

6.5MEDIUM

Key Information:

Vendor
Veritas
Status
Vendor
CVE Published:
3 October 2022

Summary

A local access vulnerability was identified in Veritas NetBackup and associated products. The issue arises when an attacker with local access sends a specially crafted packet to the pbx_exchange component during registration. This action can trigger a NULL pointer exception, ultimately leading to a crash of the pbx_exchange process. Organizations utilizing affected versions of Veritas NetBackup should assess their systems' security configurations to mitigate potential exploitation.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.