Vulnerability CVE-2007-5328


Published: 2007-10-12   Modified: 2012-02-12

Description:
The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure."

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
CA -> Brightstor arcserve backup 
CA -> Brightstor enterprise backup 

 References:
http://supportconnectw.ca.com/public/storage/infodocs/basb-secnotice.asp
http://www.securityfocus.com/archive/1/482121/100/0/threaded
http://www.securityfocus.com/archive/1/484229/100/0/threaded
http://www.securityfocus.com/bid/26015
http://www.securitytracker.com/id?1018805
http://www.vupen.com/english/advisories/2007/3470
http://www.zerodayinitiative.com/advisories/ZDI-07-069.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/37067

Copyright 2024, cxsecurity.com

 

Back to Top