CVE-2005-0491 is a critical stack-based buffer overflow vulnerability affecting Knox Arkeia Server Backup versions 5.3.x, triggered by the improper handling of long type 77 requests. With a maximum CVSS score of 10.0, this flaw allows unauthenticated remote attackers to execute arbitrary code with low attack complexity, resulting in a complete compromise of system confidentiality, integrity, and availability. While there is no recent evidence of active campaigns or inclusion in the CISA Known Exploited Vulnerabilities catalog, the risk remains significant due to the public availability of functional exploit code within the Metasploit Framework and ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.3.0CPE matchmatch criteria | cpe:2.3:a:knox_software:arkeia_server_backup:5.3.0:*:*:*:*:*:*:* | ||
5.3.0_rc1CPE matchmatch criteria | cpe:2.3:a:knox_software:arkeia_server_backup:5.3.0_rc1:*:*:*:*:*:*:* | ||
5.3.0_rc2CPE matchmatch criteria | cpe:2.3:a:knox_software:arkeia_server_backup:5.3.0_rc2:*:*:*:*:*:*:* | ||
5.3.0_rc3CPE matchmatch criteria | cpe:2.3:a:knox_software:arkeia_server_backup:5.3.0_rc3:*:*:*:*:*:*:* | ||
5.3.0_rc4CPE matchmatch criteria | cpe:2.3:a:knox_software:arkeia_server_backup:5.3.0_rc4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.