Log File Overwrite Vulnerability in Veritas NetBackup
CVE-2023-28758

7.1HIGH

Key Information:

Vendor
Veritas
Status
Vendor
CVE Published:
23 March 2023

Summary

A vulnerability exists in Veritas NetBackup, allowing unauthorized users to specify a custom log file path when executing certain commands. This flaw can lead to the overwriting of existing log files, potentially compromising the integrity of backup logs and exposing sensitive information. It is crucial for users to upgrade to version 8.3.0.2 or later to mitigate this risk.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.