Arcserve Vulnerabilities and Affected Products
Vulnerabilities associated with arcserve_unified_data_protection.
Products
Clear product- Unified Data Protection (UDP)5 vulnerabilities
- Unified Data Protection4 vulnerabilities
- Arcserve UDP3 vulnerabilities
- arcserve_unified_data_protection2 vulnerabilities
- udp2 vulnerabilities
- D2D1 vulnerability
- UDP Console1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-0800HIGH | Authentication Bypass via wizardLogin in Arcserve Unified Data ProtectionA path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet. CWE-434Mar 13, 2024 | CVSS8.8v3.1 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0799CRITICAL | Authentication Bypass via wizardLogin in Arcserve Unified Data ProtectionAn authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. | CVSS9.8v3.1 | EPSS4.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |