nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-41998 CVE-2023-41998
CRITICAL
Arcserve UDP Unauthenticated RCE
Record summary
CVE-2023-41998 has a selected CVSS score of 9.8 (critical).
Description
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Arcserve UDPBrowse Arcserve / Arcserve UDPDefault status: unaffected | CVE List | Before 9.2 | affected |
References
2tenable.com
https://www.tenable.com/security/research/tra-2023-37