Lucene search

K
cveMitreCVE-2008-5415
HistoryDec 11, 2008 - 3:30 p.m.

CVE-2008-5415

2008-12-1115:30:00
mitre
web.nvd.nist.gov
30
cve-2008-5415
ldbserver
remote attackers
execute arbitrary code
rpc endpoint
handle_t argument
incompatible procedure
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.24

Percentile

96.6%

The LDBserver service in the server in CA ARCserve Backup 11.1 through 12.0 on Windows allows remote attackers to execute arbitrary code via a handle_t argument to an RPC endpoint in which the argument refers to an incompatible procedure.

Affected configurations

Nvd
Node
broadcomarcserve_backupMatchr12.0
OR
caarcserve_backupMatchr11.1
OR
caarcserve_backupMatchr11.5
AND
microsoftwindows
VendorProductVersionCPE
broadcomarcserve_backupr12.0cpe:2.3:a:broadcom:arcserve_backup:r12.0:*:*:*:*:*:*:*
caarcserve_backupr11.1cpe:2.3:a:ca:arcserve_backup:r11.1:*:*:*:*:*:*:*
caarcserve_backupr11.5cpe:2.3:a:ca:arcserve_backup:r11.5:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.24

Percentile

96.6%