Arcserve Vulnerabilities and Affected Products
Vulnerabilities associated with Arcserve UDP.
Products
Clear product- Unified Data Protection (UDP)5 vulnerabilities
- Unified Data Protection4 vulnerabilities
- Arcserve UDP3 vulnerabilities
- arcserve_unified_data_protection2 vulnerabilities
- udp2 vulnerabilities
- D2D1 vulnerability
- UDP Console1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-42000CRITICAL | Arcserve UDP Agent Unauthenticated Path Traversal File UploadArcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed. CWE-22Nov 27, 2023 | CVSS9.8v3.1 | EPSS1.47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41999CRITICAL | Arcserve UDP Management Authentication BypassAn authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication. CWE-287Nov 27, 2023 | CVSS9.8v3.1 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-41998CRITICAL | Arcserve UDP Unauthenticated RCEArcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files. CWE-434Nov 27, 2023 | CVSS9.8v3.1 | EPSS15.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |