VTS24-009
Security Advisory affecting NetBackup Flex Scale Appliance
Revision History
- 1.0: September 17, 2024: Initial version
- 2.0 October 31, 2024: Final version
Issue: NetBackup Flex Scale Appliance impacted by Tianocore EDK2 Buffer Underwrite
Tianocore EDK2 contains a buffer underwrite flaw. Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
CVE ID: CVE-2021-38578
Severity: High
CVSS v3.1 Base Score 7.4 (AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L)
CWE-787 - Out-of-bounds Write
Affected Components: NetBackup Flex Scale Appliance 5551 and 5561
Affected Versions: 3.1, 3.2, and 3.2.100
Recommended Action:
- 5551 Appliance: Apply Firmware package for NetBackup Flex Scale 5551 appliance (version 202404.01 or above)
- 5561 Appliance: Apply Firmware package for NetBackup Flex Scale 5561 appliance (version 202404.01 or above)
Questions
For questions or problems regarding these vulnerabilities please contact Veritas Technical Support (https://www.veritas.com/support/en_US/contact-us)
Disclaimer
THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.
Veritas Technologies LLC
2625 Augustine Drive
Santa Clara, CA 95054