SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0060

Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain…

HIGH 9.3EPSS 23.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 23.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
23.64% probability · 98th percentile
CISA KEV
Not listed
Affected
broadcom/advantage data transport · broadcom/brightstor portal · broadcom/brightstor san manager · broadcom/cleverpath aion · broadcom/cleverpath ecm · broadcom/cleverpath olap · broadcom/cleverpath predictive analysis server · broadcom/etrust admin · broadcom/unicenter application performance monitor · broadcom/unicenter asset management · broadcom/unicenter data transport option · broadcom/unicenter jasmine · broadcom/unicenter network and systems management · broadcom/unicenter nsm wireless network management option · broadcom/unicenter remote control · broadcom/unicenter service level management · broadcom/unicenter software delivery · broadcom/unicenter tng · ca/etrust admin · ca/unicenter asset management · +4 more
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.