CVE-2007-5006

CA BrightStor ARCserve Backup r11.0-r11.5 - Unauthenticated Remote User Management

Title source: llm
STIX 2.1

Description

Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.

References (8)

Core 8
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25606
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=598
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24348
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/480252/100/100/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018728

Scores

EPSS 0.0186
EPSS Percentile 83.3%

Details

CWE
CWE-287
Status published
Products (8)
broadcom/brightstor_arcserve_backup_laptops_desktops 4.0
broadcom/brightstor_arcserve_backup_laptops_desktops 11.0
broadcom/brightstor_arcserve_backup_laptops_desktops 11.1 (2 CPE variants)
broadcom/brightstor_arcserve_backup_laptops_desktops 11.5
broadcom/desktop_management_suite 11.0
broadcom/desktop_management_suite 11.1
broadcom/desktop_management_suite 11.2
ca/protection_suites r2
Published Oct 01, 2007
Tracked Since Feb 18, 2026