Impact
The vulnerability originates from the NVBULibraryPort JSON‑RPC interface in Quest NetVault Backup, where an unsanitized user‑supplied string is used to build SQL statements. This oversight permits SQL injection that can ultimately lead to arbitrary code execution. The flaw subsists even though authentication is ostensibly required; however, the existing authentication scheme can be subverted, enabling attackers to gain the privileges of the NETWORK SERVICE account.
Affected Systems
Any deployment of Quest NetVault Backup is potentially impacted. The vulnerability is tied to the NVBULibraryPort component, but the affected product version is not explicitly enumerated in the publicly available data. Administrators should confirm whether their installations include that interface and review recent release notes for patches or mitigations.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as severe, and the lack of an available EPSS score indicates insufficient data on current exploitation rates, yet the historical evidence of a zero‑day advisory (ZDI-CAN-27631) suggests active exploitation. Because authentication can be bypassed, the risk is elevated to remote attackers who can gain system‑level code execution if the affected service is exposed to the network. The vulnerability is not listed in the CISA KEV catalog, however its potential impact warrants proactive countermeasures.
OpenCVE Enrichment