CVE Vulnerabilities

CVE-2022-41320

Insecure Storage of Sensitive Information

Published: Sep 23, 2022 | Modified: May 27, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
System_recoveryVeritas18.0 (including)18.0.4.57090 (excluding)
System_recoveryVeritas21 (including)21.0.3.62140 (excluding)

References