CVE-2005-1272 describes a stack-based buffer overflow vulnerability in the Backup Agent for Microsoft SQL Server within BrightStor ARCserve Backup Agent for SQL Server 11.0 and related Broadcom/CA products. This flaw allows remote attackers to execute arbitrary code by sending a specially crafted long string to ports 6070 or 6050. The vulnerability carries a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Its high EPSS and FAUCET Risk Score of 99/100 further emphasize its exploitability and impact. While not currently on the CISA KEV catalog, exploit code is publicly available, including a Metasploit module and entries on ExploitDB. Despite this, there is no significant community discussion or media coverage surrounding this CVE, which is typical for a vulnerability of this age.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_enterprise_backup:10.0:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_enterprise_backup:10.5:*:*:*:*:*:*:* | ||
9.0.1CPE matchmatch criteria | cpe:2.3:a:ca:brightstor_arcserve_backup:9.0.1:*:windows:*:*:*:*:* | ||
9.0_1CPE matchmatch criteria | cpe:2.3:a:ca:brightstor_arcserve_backup:9.0_1:*:oracle:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:ca:brightstor_arcserve_backup:11.0:*:oracle:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.