CVE-2007-5006
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 21.18% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- broadcom/brightstor arcserve backup laptops desktops · broadcom/desktop management suite · ca/protection suites
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=598
- http://secunia.com/advisories/25606Vendor Advisory
- http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.aspPatch
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006Patch
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35677Patch
- http://www.securityfocus.com/archive/1/480252/100/100/threaded
- http://www.securityfocus.com/bid/24348
- http://www.securitytracker.com/id?1018728
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=598
- http://secunia.com/advisories/25606Vendor Advisory
- http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.aspPatch
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006Patch
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35677Patch
- http://www.securityfocus.com/archive/1/480252/100/100/threaded
- http://www.securityfocus.com/bid/24348
- http://www.securitytracker.com/id?1018728
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.