CVE-2017-6406: Veritas Access

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.

Affected products

  • Veritas Access: up to and including 7.2.1
  • Veritas Netbackup: up to and including 7.7.1
  • Veritas Netbackup Appliance: up to and including 2.7.1

Published 2017-03-02. Last modified 2026-06-17.