Vulnerability identifier: #VU74470
Vulnerability risk: High
CVSSv4.0: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Amber]
CVE-ID:
CWE-ID:
CWE-287
Exploitation vector: Network
Exploit availability: Yes
Vulnerable software:
Backup Exec
Client/Desktop applications /
Multimedia software
Vendor: Veritas Technologies
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to an error in SHA Authentication scheme. A remote user can use specially crafted input parameters on one of the data management protocol commands to access an arbitrary file on the system using System privileges.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Backup Exec: 16 FP1 (16.0.1142.1327) - 21.1
External links
https://www.veritas.com/content/support/en_US/security/VTS21-001#issue2
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
Yes. This vulnerability is being exploited in the wild.