CVE-2022-36951
Last modified
CVE-2022-36951 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Veritas | Netbackup | >= 8.0, < 8.3.0.2 |
| Veritas | Netbackup | 9.0 |
| Veritas | Netbackup | 9.1.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36951?
How severe is CVE-2022-36951?
How do I fix CVE-2022-36951?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36946nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux…7.5
- CVE-2022-36947Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer…9.8
- CVE-2022-36948In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. …5.4
- CVE-2022-36949In Veritas NetBackup OpsCenter, an attacker with local acces…7.8
- CVE-2022-3695 Hitachi Vantara Pentaho Business Analytics Server prior to …6.1
- CVE-2022-36950In Veritas NetBackup OpsCenter, an unauthenticated remote at…9.8
- CVE-2022-36952In Veritas NetBackup OpsCenter, a hard-coded credential exis…9.8
- CVE-2022-36953In Veritas NetBackup OpsCenter, certain endpoints could allo…4.3
- CVE-2022-36954In Veritas NetBackup OpsCenter, under specific conditions, a…6.5
- CVE-2022-36955In Veritas NetBackup, an attacker with unprivileged local ac…8.4
- CVE-2022-36956In Veritas NetBackup, the NetBackup Client allows arbitrary …7.5
- CVE-2022-36957SolarWinds Platform was susceptible to the Deserialization o…7.2
Are you affected by CVE-2022-36951?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
