ZeroHour

CVE-2015-4068

KEVlarge

Directory Traversal Vulnerability in Arcserve Unified Data Protection (UDP)

CISA: Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

CVSS
EPSS
64%p99
Published
KEV added
AI analysis

CVE-2015-4068 is a directory traversal flaw (CWE-22) in Arcserve Unified Data Protection (UDP), Arcserve's backup and disaster recovery platform. A remote attacker can trigger it by submitting crafted requests containing directory traversal sequences to the affected UDP component, causing the software to access files outside the intended directory. Successful exploitation can disclose sensitive information accessible to the server or crash the service, resulting in a denial of service. Any organization running an affected Arcserve UDP deployment is potentially exposed; the available data does not specify affected version ranges, so administrators should compare their installed version against Arcserve's advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming in-the-wild exploitation (ransomware association unconfirmed), and EPSS assigns a 63.6% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known.

What to do: Apply the updates prescribed in Arcserve's advisory, as required by the CISA KEV listing's mandated action to patch per vendor instructions. Until patched, limit internet exposure of UDP management consoles and related services and review access logs for directory traversal patterns. Because the available data does not list affected versions, verify your installed UDP version against the Arcserve advisory before remediation.

Affected
Arcserve Unified Data Protection (UDP)
Estimated exposure
largelikely on the order of 10,000-100,000 installations worldwide; number of internet-exposed instances unknown — Arcserve UDP is a broadly deployed mid-market/enterprise backup product with a large legacy installed base, but no public install counts or internet-exposure scan data exist, so this is a rough deployment-pattern estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

CISA Known Exploited Vulnerability
Affected
Arcserve Unified Data Protection (UDP)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Arcserve
Products
Unified Data Protection (UDP)
Weakness
CWE-22

In the news