Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-18780


An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.


Published

2019-11-05T20:15:11.203

Last Modified

2024-11-21T04:33:33.170

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application veritas access ≤ 7.4.2 Yes
Application veritas access_appliance ≤ 7.4.2 Yes
Application veritas flex_appliance ≤ 1.2 Yes
Application veritas infoscale ≤ 7.3.1 Yes
Application veritas infoscale ≤ 7.4.1 Yes
Application veritas cluster_server ≤ 6.1 Yes
Application veritas storage_foundation_ha ≤ 6.1 Yes
Operating System microsoft windows - No
Application veritas cluster_server ≤ 6.2.1 Yes
Application veritas storage_foundation_ha ≤ 6.2.1 Yes
Operating System linux linux_kernel - No

References