Arcserve Vulnerabilities and Affected Products
Vulnerabilities associated with udp.
Products
Clear product- Unified Data Protection (UDP)5 vulnerabilities
- Unified Data Protection4 vulnerabilities
- Arcserve UDP3 vulnerabilities
- arcserve_unified_data_protection2 vulnerabilities
- udp2 vulnerabilities
- D2D1 vulnerability
- UDP Console1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-0801HIGH | Unauthenticated DoS in Arcserve Unified Data ProtectionA denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll. | CVSS7.5v3.1 | EPSS41.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-26258CRITICAL | arcserve udp Incorrect AuthorizationArcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator. | CVSS9.8v3.1 | EPSS37.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |