PatchSiren cyber security CVE debrief
CVE-2017-6404 Veritas CVE debrief
CVE-2017-6404 is a log-integrity issue in Veritas NetBackup and NetBackup Appliance. According to NVD and the vendor advisory reference, affected installations used world-writable log files, which can let a local user destroy or spoof log data. The issue is rated medium severity (CVSS 5.5) and maps to improper file permissions (CWE-276).
- Vendor
- Veritas
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-02
- Advisory updated
- 2026-05-13
Who should care
Veritas NetBackup and NetBackup Appliance administrators, security teams responsible for server hardening, and anyone relying on these logs for auditing, incident response, or compliance.
Technical summary
NVD lists the vulnerability as affecting Veritas NetBackup up to 7.6.1.2 and NetBackup Appliance up to 2.6.1.2. The weakness is that log files were world-writable, so a local attacker with limited privileges could modify or destroy log content, undermining auditability and trust in records. The NVD CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) indicates a local, low-privilege integrity impact without confidentiality or availability impact.
Defensive priority
Medium. This is not a remote code execution issue, but it can undermine incident response and audit evidence. Prioritize if these systems are used for compliance logging or security monitoring.
Recommended defensive actions
- Upgrade affected Veritas NetBackup and NetBackup Appliance installations to vendor-fixed versions.
- Review permissions on NetBackup log files and directories to ensure they are not world-writable.
- Restrict local shell and service access to trusted administrators only.
- Monitor for unexpected log truncation, deletion, or tampering indicators.
- Validate log integrity where possible by using centralized or append-only logging controls.
Evidence notes
The corpus identifies the issue as a world-writable log file problem in Veritas NetBackup / NetBackup Appliance, cites CWE-276, and provides the NVD CVSS 3.0 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N. The NVD CPE criteria in the supplied source mark NetBackup through 7.6.1.2 and NetBackup Appliance through 2.6.1.2 as vulnerable. The vendor advisory reference is VTS17-003 Issue9.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6404 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6404
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6404 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6404
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.veritas.com/content/support/en_US/security/VTS17-003.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.