CVE-2023-37237: Veritas Netbackup Appliance

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

In Veritas NetBackup Appliance before 4.1.0.1 MR3, insecure permissions may allow an authenticated Admin to bypass shell restrictions and execute arbitrary operating system commands via SSH.

Affected products

  • Veritas Netbackup Appliance: before 4.1.0.1 (fixed in 4.1.0.1); version 4.1.0.1 only

Published 2023-06-29. Last modified 2026-06-17.