Unauthorized File Access in Veritas System Recovery by Veritas
CVE-2024-35204

8.4HIGH

Key Information:

Vendor

Veritas

Vendor
CVE Published:
14 May 2024

What is CVE-2024-35204?

The vulnerability in Veritas System Recovery arises from improper permission settings for the System Recovery folder. This flaw allows users with low privileges to exploit file access and potentially execute unauthorized actions. Organizations using versions prior to 23.3_Hotfix should be aware of this risk and implement necessary precautions to mitigate the exposure.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.