Impact
An authenticated user with access to the NetBackup Flex OS management shell can supply a specially crafted path argument to a diagnostic command, enabling the read of arbitrary files from the underlying operating system. The vulnerability is a relative path traversal flaw classified as CWE‑347. Successful exploitation could expose sensitive system configuration files and credential material stored on the appliance, compromising confidentiality of the appliance’s internal data.
Affected Systems
The affected product is Cohesity NetBackup Flex OS. No specific versions are listed in the advisory; organizations should verify the applicability of the vulnerability to their deployed appliance versions.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. EPSS is <1%, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the management shell, so the risk is primarily internal. Nonetheless, an attacker who gains privileged shell access could exfiltrate configuration and credential files, potentially enabling broader compromise of the environment.
OpenCVE Enrichment