Veritas InfoScale Operations Manager prior to 8.0.0.410 Insecure File Upload (VTS23-009)

high Nessus Plugin ID 178720

Synopsis

A storage management application installed on the remote host is affected by multiple vulnerabilities.

Description

The Veritas InfoScale Operations Manager application installed on the remote host is prior to 8.0.0.410. It is, therefore, affected by an insecure file upload vulnerability.

- The VIOM XPRTLD web application allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
(CVE-2023-38404)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version

Solution

Upgrade to Veritas InfoScale Operations Manager version 8.0.0.410 or later.

See Also

https://www.veritas.com/content/support/en_US/security/VTS23-009

Plugin Details

Severity: High

ID: 178720

File Name: veritas_infoscale_operations_manager_VTS23-009.nasl

Version: 1.4

Type: local

Agent: windows, macosx, unix

Family: CGI abuses

Published: 7/21/2023

Updated: 7/28/2023

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-38404

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:veritas:infoscale_operations_manager

Required KB Items: installed_sw/Veritas InfoScale Operations Manager

Exploit Ease: No known exploits are available

Patch Publication Date: 7/12/2023

Vulnerability Publication Date: 7/12/2023

Reference Information

CVE: CVE-2023-38404

IAVB: 2023-B-0054-S