VulnerabilityModified
CVE-2006-6076
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.
HIGH 10.0EPSS 70.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 70.86% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- broadcom/brightstor arcserve backup · ca/brightstor arcserve backup · ca/brightstor arcserve backup agent
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050808.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050814.html
- http://secunia.com/advisories/23060Vendor Advisory
- http://secunia.com/advisories/24512
- http://securitytracker.com/id?1017268
- http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp
- http://www.kb.cert.org/vuls/id/437300US Government Resource
- http://www.securityfocus.com/archive/1/452222/100/0/threaded
- http://www.securityfocus.com/archive/1/452318/100/0/threaded
- http://www.securityfocus.com/archive/1/456711
- http://www.securityfocus.com/bid/21221
- http://www.vupen.com/english/advisories/2006/4654
- http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34817
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30453
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050808.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-November/050814.html
- http://secunia.com/advisories/23060Vendor Advisory
- http://secunia.com/advisories/24512
- http://securitytracker.com/id?1017268
- http://supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp
- http://www.kb.cert.org/vuls/id/437300US Government Resource
- http://www.securityfocus.com/archive/1/452222/100/0/threaded
- http://www.securityfocus.com/archive/1/452318/100/0/threaded
- http://www.securityfocus.com/archive/1/456711
- http://www.securityfocus.com/bid/21221
- http://www.vupen.com/english/advisories/2006/4654
- http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=101317
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34817
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30453
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.