Advertisement






Veritas Resiliency Platform (VRP) Traversal / Command Execution

CVE Category Price Severity
CVE-2019-14415 CWE-22 $10,000 High
Author Risk Exploitation Type Date
Tripwire VERT Critical Remote 2019-08-01
CPE
cpe:cpe:/a:veritas:resiliency_platform
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H 0.54508 0.89898

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019080002

Below is a copy:

Veritas Resiliency Platform (VRP) Traversal / Command Execution
Four vulnerabilities have been fixed in VRP 3.4 HF1, one of which is of critical severity.

Directory traversal vulnerability related to uploading application bundles
CVE-2019-14415
Critical severity

Arbitrary command execution vulnerability with root privilege related to DNS server configuration
CVE-2019-14416
High severity

Arbitrary command execution vulnerability with root privilege related to resiliency plans and custom scripts
CVE-2019-14417
High severity

A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality.
CVE-2019-14418
Medium severity

https://www.veritas.com/content/support/en_US/security/VTS19-002.html



Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum