CVE-2019-18780
9.8
CRITICAL · CVSS 3.1 · EPSS 6.1% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.14% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-11-05 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| linux | linux kernel |
| microsoft | windows |
| veritas | access |
| veritas | access appliance |
| veritas | cluster server |
| veritas | flex appliance |
| veritas | infoscale |
| veritas | storage foundation ha |
References
- https://www.veritas.com/content/support/en_US/security/VTS19-003
- https://www.veritas.com/content/support/en_US/security/VTS19-004
- https://www.veritas.com/content/support/en_US/security/VTS19-005
- https://www.veritas.com/content/support/en_US/security/VTS19-006
- https://www.veritas.com/content/support/en_US/security/VTS19-003
- https://www.veritas.com/content/support/en_US/security/VTS19-004
- https://www.veritas.com/content/support/en_US/security/VTS19-005
- https://www.veritas.com/content/support/en_US/security/VTS19-006
→ the Explorer · watch your stack · NVD