Record summary

CVE-2024-0801 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 9, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 13, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

VulnCheck, CVE ListThrough 9.2affected
Through 8.1affected

Default status: unknown

CVE ListThrough 9.2affected
Through 8.1affected

Nuclei templates

1
ProjectDiscoveryHIGHArcserve Unified Data Protection - Unauthenticated DoS in ASNative.dllCVSS 7.5

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

Impact

Attackers can cause system crashes or unavailability, leading to service disruption and potential downtime.

Remediation

Update to the latest version of Arcserve Unified Data Protection or apply available patches.

WeaknessesCWE-75
Authorsdaffainfo
Template tagscvecve2024arcservedosintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:1015186617
FOFA: icon_hash="1015186617"

Source: ProjectDiscovery

References

2