CVE-2015-4068
KEVlargeDirectory Traversal Vulnerability in Arcserve Unified Data Protection (UDP)
CISA: Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability
CVE-2015-4068 is a directory traversal flaw (CWE-22) in Arcserve Unified Data Protection (UDP), Arcserve's backup and disaster recovery platform. A remote attacker can trigger it by submitting crafted requests containing directory traversal sequences to the affected UDP component, causing the software to access files outside the intended directory. Successful exploitation can disclose sensitive information accessible to the server or crash the service, resulting in a denial of service. Any organization running an affected Arcserve UDP deployment is potentially exposed; the available data does not specify affected version ranges, so administrators should compare their installed version against Arcserve's advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming in-the-wild exploitation (ransomware association unconfirmed), and EPSS assigns a 63.6% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known.
What to do: Apply the updates prescribed in Arcserve's advisory, as required by the CISA KEV listing's mandated action to patch per vendor instructions. Until patched, limit internet exposure of UDP management consoles and related services and review access logs for directory traversal patterns. Because the available data does not list affected versions, verify your installed UDP version against the Arcserve advisory before remediation.
| Arcserve Unified Data Protection (UDP) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.
- Affected
- Arcserve Unified Data Protection (UDP)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Arcserve
- Products
- Unified Data Protection (UDP)
- Weakness
- CWE-22