Executive brief
Veritas InfoScale CmdServer, a component used for managing enterprise storage and clusters, contains a security flaw in how it handles access permissions. This vulnerability could allow unauthorized individuals to bypass security checks and potentially execute commands or access sensitive management functions. Such an exploit could lead to unauthorized changes to storage infrastructure or disruption of business-critical services.
Technical details
Veritas InfoScale CmdServer versions prior to 7.4.2 contain an access control vulnerability. The CmdServer component, which facilitates remote management and command execution across InfoScale clusters, fails to properly validate or enforce authorization checks. An attacker with network access to the CmdServer service could exploit this flaw to perform unauthorized actions. While specific exploitation details are limited, the vulnerability typically involves bypassing authentication or authorization logic to execute administrative commands. Users are advised to upgrade to InfoScale 7.4.2 or later to remediate this issue.
Affected products
- Veritas InfoScale CmdServer before 7.4.2
Timeline
- 2026-05-20: disclosed: Initial NVD publication date