2024-07-14 02:06:08 +00:00

48 lines
2.0 KiB
JSON

{
"id": "CVE-2024-34404",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-05-03T01:15:48.753",
"lastModified": "2024-05-03T12:50:34.250",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode images. This vulnerability allowed a NetBackup administrator to modify the expiration of backups under Governance mode (which could cause premature deletion)."
},
{
"lang": "es",
"value": "Se descubri\u00f3 una vulnerabilidad en la funci\u00f3n Alta Recovery Vault de Veritas NetBackup anterior a 10.4 y NetBackup Appliance anterior a 5.4. Por dise\u00f1o, solo el administrador de la nube deber\u00eda poder desactivar el bloqueo de retenci\u00f3n de las im\u00e1genes del modo de gobernanza. Esta vulnerabilidad permiti\u00f3 a un administrador de NetBackup modificar la caducidad de las copias de seguridad en el modo de Governance (lo que podr\u00eda provocar una eliminaci\u00f3n prematura)."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cve@mitre.org",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.3,
"impactScore": 4.0
}
]
},
"references": [
{
"url": "https://www.veritas.com/support/en_US/security/VTS24-004",
"source": "cve@mitre.org"
}
]
}