Showing 3 vulnerabilities on this page for Arcserve UDP

Signals CISA KEV Ransomware Nuclei
Arcserve vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Arcserve UDP Agent Unauthenticated Path Traversal File Upload

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

CWE-22Nov 27, 2023
CVSS9.8v3.1EPSS1.47%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Arcserve UDP Management Authentication Bypass

An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.

CWE-287Nov 27, 2023
CVSS9.8v3.1EPSS1.44%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Arcserve UDP Unauthenticated RCE

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.

CWE-434Nov 27, 2023
CVSS9.8v3.1EPSS15.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX