CVE Vulnerabilities

CVE-2017-6406

Published: Mar 02, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with ../ substrings, can occur.

Affected Software

NameVendorStart VersionEnd Version
AccessVeritas*7.2.1 (including)
NetbackupVeritas*7.7.1 (including)
Netbackup_applianceVeritas*2.7.1 (including)

References