CVE-2025-34520
- EPSS 0.22%
- Veröffentlicht 27.08.2025 21:19:43
- Zuletzt bearbeitet 09.09.2025 15:01:02
An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a log...
CVE-2025-34521
- EPSS 0.05%
- Veröffentlicht 27.08.2025 21:19:38
- Zuletzt bearbeitet 09.09.2025 14:54:27
A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privile...
CVE-2025-34522
- EPSS 0.57%
- Veröffentlicht 27.08.2025 21:19:33
- Zuletzt bearbeitet 09.09.2025 14:45:21
A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checkin...
CVE-2025-34523
- EPSS 0.44%
- Veröffentlicht 27.08.2025 21:19:26
- Zuletzt bearbeitet 09.09.2025 14:39:34
A heap-based buffer overflow vulnerability exists in the exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when proc...
CVE-2024-0799
- EPSS 51.51%
- Veröffentlicht 13.03.2024 19:15:46
- Zuletzt bearbeitet 14.10.2025 18:00:04
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
CVE-2024-0800
- EPSS 0.26%
- Veröffentlicht 13.03.2024 19:15:46
- Zuletzt bearbeitet 14.10.2025 17:29:11
A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.
CVE-2024-0801
- EPSS 63.14%
- Veröffentlicht 13.03.2024 19:15:46
- Zuletzt bearbeitet 14.10.2025 17:28:38
A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.
CVE-2023-42000
- EPSS 1.25%
- Veröffentlicht 27.11.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:22:05
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system wher...
CVE-2023-41998
- EPSS 15.29%
- Veröffentlicht 27.11.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 08:22:04
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
CVE-2023-41999
- EPSS 0.15%
- Veröffentlicht 27.11.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 08:22:05
An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentic...