Record summary

CVE-2024-0799 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 9, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

VulnCheck, CVE ListThrough 9.2affected
Through 8.1affected

Default status: unknown

CVE List9.2affected

Nuclei templates

1
ProjectDiscoveryCRITICALArcserve Unified Data Protection - Authentication BypassCVSS 9.8

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

Impact

Attackers can bypass authentication, gaining unauthorized access to the system.

Remediation

Update to the latest version of Arcserve Unified Data Protection or apply security patches provided by the vendor.

WeaknessesCWE-287
Authorsdaffainfo
Template tagscvecve2024arcserveauth-bypassvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1015186617
FOFA: icon_hash="1015186617"

Source: ProjectDiscovery

References

2