CVE-2024-0799
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
Record summary
CVE-2024-0799 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 9, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Unified Data ProtectionBrowse Arcserve / Unified Data ProtectionDefault status: unaffected | VulnCheck, CVE List | Through 9.2 | affected |
| Through 8.1 | affected | ||
arcserve_unified_data_protectionBrowse arcserve / arcserve_unified_data_protectionDefault status: unknown | CVE List | 9.2 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALArcserve Unified Data Protection - Authentication BypassCVSS 9.8
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
Impact
Attackers can bypass authentication, gaining unauthorized access to the system.
Remediation
Update to the latest version of Arcserve Unified Data Protection or apply security patches provided by the vendor.
Source: ProjectDiscovery