CVE Vulnerabilities

CVE-2022-41320

Insecure Storage of Sensitive Information

Published: Sep 23, 2022 | Modified: Sep 26, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the backup configuration. This vulnerability could provide a Windows user (who has sufficient privileges) to access a network file system that they were not authorized to access.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
System_recovery Veritas 18.0 (including) 18.0.4.57090 (excluding)
System_recovery Veritas 21 (including) 21.0.3.62140 (excluding)

References