CVE-2023-28758

An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
mitreCNA
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AC:L/AV:L/A:H/C:N/I:H/PR:L/S:U/UI:N
CVEADP
---
---
CISA-ADPADP
---
---