Vulnerabilities
17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-34522 | A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to application crashes or remote code execution. Exploitation occurs in the context of the affected process and does not require user interaction. The vulnerability poses a high risk due to its pre-authentication nature and potential for full compromise. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue. NVD description · AI analysis pending | 9.2 group max | <1% |
| — | ||
| CVE-2024-0799 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.se An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin. NVD description · AI analysis pending | 9.8 group max | 4% | PoC |
| — | |
| CVE-2023-41998 | Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files. NVD description · AI analysis pending | 9.8 | 15% | PoC |
| — | |
| CVE-2023-26258 | Arcserve UDP through 9.0.6034 allows authentication bypass. Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator. NVD description · AI analysis pending | 9.8 | 38% | PoC |
| — | |
| CVE-2020-27858 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of XML External Entity (XXE) references, a specially-crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11103. NVD description · AI analysis pending | 7.5 | 74% |
| — | ||
| CVE-2018-18659 | An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue. NVD description · AI analysis pending | 7.5 group max | 2% |
| — | ||
| CVE-2015-4068 | Directory Traversal Vulnerability in Arcserve Unified Data Protection (UDP) CVE-2015-4068 is a directory traversal flaw (CWE-22) in Arcserve Unified Data Protection (UDP), Arcserve's backup and disaster recovery platform. A remote attacker can trigger it by submitting crafted requests containing directory traversal sequences to the affected UDP component, causing the software to access files outside the intended directory. Successful exploitation can disclose sensitive information accessible to the server or crash the service, resulting in a denial of service. Any organization running an affected Arcserve UDP deployment is potentially exposed; the available data does not specify affected version ranges, so administrators should compare their installed version against Arcserve's advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming in-the-wild exploitation (ransomware association unconfirmed), and EPSS assigns a 63.6% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known. Do: Apply the updates prescribed in Arcserve's advisory, as required by the CISA KEV listing's mandated action to patch per vendor instructions. Until patched, limit internet exposure of UDP management consoles and related services and review access logs for directory traversal patterns. Because the available data does not list affected versions, verify your installed UDP version against the Arcserve advisory before remediation. | — | 64% | KEV |
| largelikely on the order of 10,000-100,000 installations worldwide; number of internet-exposed instances unknown |