An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.