CVE-2006-5143 describes multiple buffer overflow vulnerabilities in various CA BrightStor ARCserve Backup, BrightStor Enterprise Backup, and related protection suite products. These flaws allow remote attackers to execute arbitrary code by sending crafted data to specific TCP ports (6071, 6503, 41523) or through unspecified vectors related to the Job Engine Service. Rated with a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity and no authentication required, potentially leading to full compromise of confidentiality, integrity, and availability. Its high EPSS score of 0.84629 and FAUCET Risk Score of 99/100 indicate a significant threat. While not listed on CISA's KEV catalog, exploit code is publicly available, including Metasploit modules and multiple entries on ExploitDB, demonstrating its exploitability. Despite this, there is no recorded community discussion or media coverage, suggesting a lack of widespread public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.5CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:*:sp1:*:*:*:*:*:* | ||
9.01CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:9.01:*:*:*:*:*:*:* | ||
11.1CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:a:broadcom:brightstor_enterprise_backup:10.5:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:broadcom:business_protection_suite:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.