CVE-2016-7399
9.8
CRITICAL · CVSS 3.0 · EPSS 4.9% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.94% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-01-04 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| veritas | netbackup appliance |
| veritas | netbackup appliance firmware |
References
- http://www.sec-1.com/blog/2016/veritas-netbackup-appliance-unauthenticated-remote-command-execution
- http://www.securityfocus.com/bid/94384
- http://www.securitytracker.com/id/1037555
- https://www.veritas.com/content/support/en_US/security/VTS16-002.html
- https://www.veritas.com/support/en_US/article.000116055
- http://www.sec-1.com/blog/2016/veritas-netbackup-appliance-unauthenticated-remote-command-execution
- http://www.securityfocus.com/bid/94384
- http://www.securitytracker.com/id/1037555
- https://www.veritas.com/content/support/en_US/security/VTS16-002.html
- https://www.veritas.com/support/en_US/article.000116055
→ the Explorer · watch your stack · NVD