PT-2023-21941 · Veritas · Veritas Netbackup

CVE-2023-28758

·

Published

2023-03-23

·

Updated

2025-02-25

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas NetBackup versions prior to 8.3.0.2
Description An issue was discovered that allows an unprivileged user to specify a log file path when executing a NetBackup command, potentially leading to the overwrite of existing NetBackup log files.
Recommendations For versions prior to 8.3.0.2, update to version 8.3.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the BPCD functionality to prevent unprivileged users from specifying log file paths.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28758

Affected Products

Veritas Netbackup