CVE-2023-38404
Severity CVSS v4.0:
Pending analysis
Type:
CWE-434
Unrestricted Upload of File with Dangerous Type
Publication date:
17/07/2023
Last modified:
27/07/2023
Description
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:* | 7.0.0 (including) | 8.0.0.410 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



