nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-41999 CVE-2023-41999
CRITICAL
Arcserve UDP Management Authentication Bypass
Record summary
CVE-2023-41999 has a selected CVSS score of 9.8 (critical).
Description
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Arcserve UDPBrowse Arcserve / Arcserve UDPDefault status: unaffected | CVE List | Before 9.2 | affected |
References
2tenable.com
https://www.tenable.com/security/research/tra-2023-37