9.8
CVE-2022-46414
- EPSS 1.73%
- Veröffentlicht 04.12.2022 05:15:10
- Zuletzt bearbeitet 24.04.2025 14:15:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Veritas ≫ Access Appliance Version <= 8.0.100
Veritas ≫ Netbackup Flex Scale Appliance Version <= 3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.73% | 0.819 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| cve@mitre.org | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.