Medium severity6.5NVD Advisory· Published Jun 29, 2023· Updated Jun 17, 2026
CVE-2023-37237
CVE-2023-37237
Description
In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.
Affected products
5cpe:2.3:h:veritas:netbackup_appliance:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:h:veritas:netbackup_appliance:*:*:*:*:*:*:*:*range: <4.1.0.1
- cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release1:*:*:*:*:*:*
- cpe:2.3:h:veritas:netbackup_appliance:4.1.0.1:maintenance_release2:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <4.1.0.1 MR3
Patches
Vulnerability mechanics
References
1- www.veritas.com/content/support/en_US/security/VTS23-004nvdVendor Advisory
News mentions
0No linked articles in our index yet.