Back

CVE-2019-18780

CRITICAL

An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.

Published: Nov 5, 2019 Modified: Jun 17, 2026
CWE-77

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (9)

Vendor Product Version
veritas access *
veritas access_appliance *
veritas flex_appliance *
veritas infoscale *
veritas infoscale * ≥ 7.4.0
veritas cluster_server *
veritas storage_foundation_ha *
veritas cluster_server *
veritas storage_foundation_ha *

GitHub Security Advisory GHSA-86f2-fcjm-9c7w

An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.14%

Top 7% most likely to be exploited

Threat Score 41 / 100

Data Sources

NVD EPSS GitHub