Lucene search

K
cve[email protected]CVE-2007-5006
HistoryOct 01, 2007 - 8:17 p.m.

CVE-2007-5006

2007-10-0120:17:00
CWE-287
web.nvd.nist.gov
24
2
cve-2007-5006
ca brightstor arcserve backup
remote attack
user authentication
client restore

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.068 Low

EPSS

Percentile

93.9%

Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.

Affected configurations

NVD
Node
broadcombrightstor_arcserve_backup_laptops_desktopsMatch4.0
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.0
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.1
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.1sp1
OR
broadcombrightstor_arcserve_backup_laptops_desktopsMatch11.5
OR
broadcomdesktop_management_suiteMatch11.0
OR
broadcomdesktop_management_suiteMatch11.1
OR
broadcomdesktop_management_suiteMatch11.2
OR
caprotection_suitesMatchr2

Social References

More

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.068 Low

EPSS

Percentile

93.9%