Impact
A crafted argument supplied by an authenticated low‑privileged user in the NetBackup Flex OS management shell can mislead a privileged administrative command into executing arbitrary code as root. This elevates the user to full control of the appliance host and all hosted containers, thereby compromising confidentiality, integrity, and availability.
Affected Systems
Cohesity NetBackup Flex OS is the affected product. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 9.4 indicates very high severity. The EPSS score of 0.0037 indicates a very low likelihood of exploitation, and the vulnerability is not yet listed in CISA KEV. An attacker needs only local, authenticated access to the management shell and can exploit the flaw by passing a malicious argument to a privileged command, yielding unrestricted root privileges.
OpenCVE Enrichment