Impact
An authenticated low‑privileged user who can access the NetBackup Flex OS management shell can supply a specially crafted access credential that bypasses the cryptographic signature verification of a privileged support command, allowing the attacker to obtain an unrestricted root shell on the Flex appliance host. This grants full control over all hosted containers, directly compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Cohesity NetBackup Flex OS products accessed through the management shell. No specific version information is listed in the CNA data, so any deployment that provides non‑administrative shell access could be impacted until the vendor addresses the flaw.
Risk and Exploitability
The CVSS score of 9.4 classifies this as a critical vulnerability. EPSS Score is less than 1%, indicating a very low yet non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of such markers does not reduce the potential for exploitation. The likely attack vector appears to be local or through authorized administrative channels, where an attacker with low privileges can act as a privileged support operator to bypass cryptographic checks and elevate privileges.
OpenCVE Enrichment