← All CVEs

CVE-2007-5006

high · 10

Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.

10
CVSS
21.2%
EPSS (exploit prob.)
97th
EPSS percentile
2007-10-01
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
broadcombrightstor_arcserve_backup_laptops_desktops4.0
broadcombrightstor_arcserve_backup_laptops_desktops11.0
broadcombrightstor_arcserve_backup_laptops_desktops11.1
broadcombrightstor_arcserve_backup_laptops_desktops11.1
broadcombrightstor_arcserve_backup_laptops_desktops11.5
broadcomdesktop_management_suite11.0
broadcomdesktop_management_suite11.1
broadcomdesktop_management_suite11.2
caprotection_suitesr2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-5006