← Back

CVE-2019-18780

nvd nist
Published: Nov 5, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.

Affected (9)

6 products
Access
Access Appliance
Flex Appliance
Infoscale
Cluster Server
Storage Foundation Ha
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.4.2
Up to 7.4.2
Up to 1.2
Veritas
Up to 7.3.1
From 7.4.0 to 7.4.1
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.1
Up to 6.1
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.2.1
Up to 6.2.1
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (8)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.