CVE-2024-28222: Veritas Netbackup

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.

Affected products

  • Veritas Netbackup: before 8.1.2 (fixed in 8.1.2)
  • Veritas Netbackup Appliance: before 3.1.2 (fixed in 3.1.2)

Published 2024-03-07. Last modified 2026-06-17.