// For flags

CVE-2008-1329

CAarc-multi.txt

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary commands, related to "insufficient verification of file uploads."

Vulnerabilidad no especificada del servicio NetBackup de CA ARCserve Backup for Laptops and Desktops versiones de la r11.0 a la r11.5 y Suite 11.1 and 11.2, permite a atacantes remotos ejecutar comandos de su elección, relacionado con “subidas de archivos sin suficiente verificacion”

CA ARCserve Backup for Laptops and Desktops Server contains multiple vulnerabilities that can allow a remote attacker to execute arbitrary code or cause a denial of service condition. CA has issued updates to address the vulnerabilities. The first issue occurs due to insufficient bounds checking on command arguments by the LGServer service. The second issue occurs due to insufficient verification of file uploads by the NetBackup service. In most cases, an attacker can potentially gain complete control of an affected installation. Additionally, only a server installation of BrightStor ARCserve Backup for Laptops and Desktops is affected. The client installation is not affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-13 CVE Reserved
  • 2008-04-05 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Broadcom
Search vendor "Broadcom"
Desktop Management Suite
Search vendor "Broadcom" for product "Desktop Management Suite"
11.1
Search vendor "Broadcom" for product "Desktop Management Suite" and version "11.1"
-
Affected
Computer Associates
Search vendor "Computer Associates"
Arcserve Backup Laptops And Desktops
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops"
r11.0
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops" and version "r11.0"
-
Affected
Computer Associates
Search vendor "Computer Associates"
Arcserve Backup Laptops And Desktops
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops"
r11.1
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops" and version "r11.1"
-
Affected
Computer Associates
Search vendor "Computer Associates"
Arcserve Backup Laptops And Desktops
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops"
r11.1
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops" and version "r11.1"
sp1
Affected
Computer Associates
Search vendor "Computer Associates"
Arcserve Backup Laptops And Desktops
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops"
r11.1
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops" and version "r11.1"
sp2
Affected
Computer Associates
Search vendor "Computer Associates"
Arcserve Backup Laptops And Desktops
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops"
r11.5
Search vendor "Computer Associates" for product "Arcserve Backup Laptops And Desktops" and version "r11.5"
-
Affected
Computer Associates
Search vendor "Computer Associates"
Desktop Management Suite
Search vendor "Computer Associates" for product "Desktop Management Suite"
11.2
Search vendor "Computer Associates" for product "Desktop Management Suite" and version "11.2"
english
Affected
Computer Associates
Search vendor "Computer Associates"
Desktop Management Suite
Search vendor "Computer Associates" for product "Desktop Management Suite"
11.2
Search vendor "Computer Associates" for product "Desktop Management Suite" and version "11.2"
localized
Affected