[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-5328Date: (C)2007-10-12   (M)2023-12-22


The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitrary code by using certain "insecure method calls" to modify the file system and registry, aka "Privileged function exposure."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1018805
20071011
http://www.securityfocus.com/archive/1/482121/100/0/threaded
http://www.securityfocus.com/archive/1/484229/100/0/threaded
BID-26015
SECUNIA-27192
ADV-2007-3470
ca-brightstor-unspecified-security-bypass(37067)
http://supportconnectw.ca.com/public/storage/infodocs/basb-secnotice.asp
http://www.zerodayinitiative.com/advisories/ZDI-07-069.html

CPE    1
cpe:/a:broadcom:brightstor_enterprise_backup:10.5
CWE    1
CWE-264

© SecPod Technologies