Executive brief
Quest NetVault Backup, a data protection and recovery solution, contains a security flaw in its web management interface. A remote attacker could trick a user into visiting a malicious link, allowing the attacker to bypass authentication and gain unauthorized access to the system. If combined with other flaws, this could allow an attacker to take full control of the backup server and its data.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists within the 'addclient3' webpage of Quest NetVault Backup due to insufficient validation of user-supplied data. A remote, unauthenticated attacker can exploit this by inducing a user to visit a specially crafted URL or open a malicious file, leading to arbitrary script execution in the victim's browser session. This flaw specifically enables an authentication bypass. According to the advisory, this vulnerability can be chained with other issues to achieve arbitrary code execution with SYSTEM privileges. The issue is resolved in version 14.0.2.
Affected products
- Quest NetVault Backup 14.0.1.7
Timeline
- 2025-09-24: disclosed: Vulnerability reported to vendor via ZDI
- 2026-06-24: patched: Vendor released version 14.0.2 to address the issue
- 2026-06-24: advisory: Coordinated public release of advisory