Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CA Technologies - A Broadcom Company

First CVE: Oct 20, 2000Active for: 26 yearsTotal CVEs: 138
50.6
VTI Score
TOP TARGET

CA Technologies, now a Broadcom subsidiary, maintains a moderately broad portfolio of enterprise backup, security, and systems-management products that serve large organizations, including BrightStor ArcServe Backup, eTrust Secure Content Manager, and various protection suites. Its vulnerability disclosures recur across input-handling and memory-safety weakness classes—particularly cross-site scripting, improper input validation, and buffer-boundary issues—that are characteristic of large, legacy enterprise software managing sensitive data and system access. The vendor's exposures frequently acquire public exploit code, making its advisories operationally significant despite a measured severity profile. Defenders should prioritize this vendor's updates for internet-reachable backup and security appliances, as these products often hold administrative credentials and control over critical infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
138
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by CA Technologies - A Broadcom Company over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Mar 26, 2021
1,946 days ago

Self-Reporting Analysis

Of all the CVEs published by CA Technologies - A Broadcom Company as a CNA, 22.0% affect products that CA Technologies - A Broadcom Company develops as a vendor.

22.0%
78.0%
Self-reported: 20 (22.0%)
Third-party: 71 (78.0%)

Of all the CVEs published that affect products developed by CA Technologies - A Broadcom Company, 14.5% are self-published by CA Technologies - A Broadcom Company as a CNA.

14.5%
85.5%
Self-published: 20 (14.5%)
Other CNAs: 118 (85.5%)

Products(107 total)

Top CVEs

Signals from CVEs in this vendor scope (138 CVEs).

138 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-4397HIGH
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to exec
Oct 14, 200810.084NOYES
CVE-2005-2668HIGH
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arb
Aug 23, 200510.084NOYES
CVE-2007-2139HIGH
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 throu
Apr 25, 200710.083NOYES
CVE-2007-5003HIGH
Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allow remote attackers to execute arbitrar
Oct 1, 200710.081NOYES
CVE-2006-6076HIGH
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code
Nov 24, 200610.080NOYES
CVE-2006-5143HIGH
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Se
Oct 10, 20067.578NOYES
CVE-2011-3011MEDIUM
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, vi
Aug 15, 20115.074NOYES
CVE-2005-1272HIGH
Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code v
Aug 5, 20057.574NOYES
CVE-2007-2864HIGH
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary
Jun 6, 20079.373NOYES
CVE-2004-0932HIGH
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via
Jan 27, 20057.571NOYES
View all 138 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products138 CVEs
33%
61%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (2.9%)
Network27 (19.6%)
Unknown107 (77.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (22.5%)
High0 (0.0%)
Unknown107 (77.5%)
User Interaction
None23 (16.7%)
Unknown107 (77.5%)
Required8 (5.8%)
Privileges Required
Low12 (8.7%)
High0 (0.0%)
None19 (13.8%)
Unknown107 (77.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (138 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
12 CVEs
8.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
29 CVEs
21.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by CA Technologies - A Broadcom Company.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by CA Technologies - A Broadcom Company — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For CA Technologies - A Broadcom Company's Products

View all 3 CNAs →

Top CWEs