Arcserve Backup
Vendor:
First CVE: Nov 12, 1998 · Active for 27 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Arcserve Backup over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 12, 1998
27 years ago
Most Recent CVE
Mar 22, 2012
5,238 days ago
CVE Severity & Scoring
Arcserve Backup12 CVEs
8%
58%
33%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown12 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown12 (100.0%)
User Interaction
None0 (0.0%)
Unknown12 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown12 (100.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4397HIGH Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to exec | Oct 14, 2008 | 10.0 | 84 | NO | YES |
CVE-2008-5415HIGH The LDBserver service in the server in CA ARCserve Backup 11.1 through 12.0 on Windows allows remote attackers to execute arbitrary code via a handle_t argument to an RPC endpoint | Dec 11, 2008 | 10.0 | 28 | NO | NO |
CVE-2001-0960HIGH Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden shar | Sep 15, 2001 | 10.0 | 25 | NO | NO |
CVE-1999-1049HIGH ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password. | Feb 21, 1999 | 10.0 | 25 | NO | NO |
CVE-2012-1662MEDIUM CA ARCserve Backup r12.0 through SP2, r12.5 before SP2, r15 through SP1, and r16 before SP1 on Windows allows remote attackers to cause a denial of service (service shutdown) via a | Mar 22, 2012 | 5.0 | 19 | NO | NO |
CVE-2008-4399MEDIUM Unspecified vulnerability in the database engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to c | Oct 14, 2008 | 5.0 | 19 | NO | NO |
CVE-2001-0959MEDIUM Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwr | Sep 15, 2001 | 6.4 | 18 | NO | NO |
CVE-2008-4400MEDIUM Unspecified vulnerability in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause a denial of service (crash | Oct 14, 2008 | 5.0 | 17 | NO | NO |
CVE-2008-4398MEDIUM Unspecified vulnerability in the tape engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to cause | Oct 14, 2008 | 5.0 | 17 | NO | NO |
CVE-2009-3588MEDIUM Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) th | Oct 13, 2009 | 4.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Arcserve Backup
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| r16.0 | 1 | 5.0 | 2.2% | 0 | 0 |
| r12.0 | 6 | 6.2 | 16.2% | 0 | 1 |
| 6.61 | 3 | 5.9 | 2.3% | 0 | 1 |