VulnerabilityModified
CVE-2007-2772
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.
HIGH 7.8EPSS 12.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 12.06% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- ca/brightstor arcserve backup
- Source
- cve@mitre.org
References
- http://osvdb.org/35327
- http://osvdb.org/35328
- http://secunia.com/advisories/25300Vendor Advisory
- http://securityreason.com/securityalert/2727
- http://supportconnectw.ca.com/public/storage/infodocs/babmedservul-secnotice.asp
- http://www.securityfocus.com/archive/1/468784/100/0/threaded
- http://www.securitytracker.com/id?1018076
- http://www.vupen.com/english/advisories/2007/1849
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34319
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34322
- https://www.exploit-db.com/exploits/3939
- https://www.exploit-db.com/exploits/3940
- http://osvdb.org/35327
- http://osvdb.org/35328
- http://secunia.com/advisories/25300Vendor Advisory
- http://securityreason.com/securityalert/2727
- http://supportconnectw.ca.com/public/storage/infodocs/babmedservul-secnotice.asp
- http://www.securityfocus.com/archive/1/468784/100/0/threaded
- http://www.securitytracker.com/id?1018076
- http://www.vupen.com/english/advisories/2007/1849
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34319
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34322
- https://www.exploit-db.com/exploits/3939
- https://www.exploit-db.com/exploits/3940
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.