CVE-2019-18780 Information
Description
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier Access Appliance 7.4.2 and earlier Flex Appliance 1.2 and earlier InfoScale 7.3.1 and earlier InfoScale between 7.4.0 and 7.4.1 Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX Veritas Cluster Server (VCS) 6.1 and earlier on Windows Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.veritas.com/content/support/en_US/security/VTS19-003 https://www.veritas.com/content/support/en_US/security/VTS19-004 https://www.veritas.com/content/support/en_US/security/VTS19-005 https://www.veritas.com/content/support/en_US/security/VTS19-006
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: