Lucene search

K
cveMitreCVE-2007-5003
HistoryOct 01, 2007 - 8:17 p.m.

CVE-2007-5003

2007-10-0120:17:00
CWE-119
mitre
web.nvd.nist.gov
37
2
cve-2007-5003
buffer overflow
ca brightstor arcserve backup
remote code execution
rxrpc.dll

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.937

Percentile

99.2%

Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrary code via a long (1) username or (2) password to the rxrLogin command in rxRPC.dll, or a long (3) username argument to the GetUserInfo function.

Affected configurations

Nvd
Node
broadcombrightstor_arcserve_backup_laptops_desktopsMatch4.0
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.0
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.1
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.1sp1
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.5
OR
broadcomdesktop_management_suiteMatch11.0
OR
broadcomdesktop_management_suiteMatch11.1
OR
broadcomdesktop_management_suiteMatch11.2
OR
caprotection_suitesMatchr2
VendorProductVersionCPE
broadcombrightstor_arcserve_backup_laptops_desktops4.0cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:4.0:*:*:*:*:*:*:*
broadcombrightstor_arcserve_backup_laptops_desktops11.0cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*
broadcombrightstor_arcserve_backup_laptops_desktops11.1cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*
broadcombrightstor_arcserve_backup_laptops_desktops11.1cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*
broadcombrightstor_arcserve_backup_laptops_desktops11.5cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.5:*:*:*:*:*:*:*
broadcomdesktop_management_suite11.0cpe:2.3:a:broadcom:desktop_management_suite:11.0:*:*:*:*:*:*:*
broadcomdesktop_management_suite11.1cpe:2.3:a:broadcom:desktop_management_suite:11.1:*:*:*:*:*:*:*
broadcomdesktop_management_suite11.2cpe:2.3:a:broadcom:desktop_management_suite:11.2:*:*:*:*:*:*:*
caprotection_suitesr2cpe:2.3:a:ca:protection_suites:r2:*:*:*:*:*:*:*

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.937

Percentile

99.2%