CRITICAL
Arcserve UDP through 9.0.6034 allows authentication bypass
Published Jul 3, 2023
9.8
CRITICALCVSS 3.1
EPSS 39.77%
Description
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-30082 Advisory
- https://support.arcserve.com/s/article/KB000015720?language=en_US
- https://www.arcserve.com/products/arcserve-udp Product
- https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/ ExploitTechnical DescriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-30082 | Advisory | |
| https://support.arcserve.com/s/article/KB000015720?language=en_US | ||
| https://www.arcserve.com/products/arcserve-udp | Product | |
| https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/ | ExploitTechnical DescriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 3, 2023
Updated Nov 25, 2024
Reserved Feb 21, 2023
Link CVE-2023-26258
CISA Vulnrichment
Updated Nov 25, 2024
ENISA EUVD
EUVD-2023-30082 Assigner mitre
Published Jul 3, 2023
Updated Nov 25, 2024
Exploited since n/a
Link EUVD-2023-30082