PT-2001-2112 · Computer Associates · Arcserve 2000+1

Publicado

2001-09-15

·

Atualizado

2021-04-07

·

CVE-2001-0960

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Computer Associates ARCserve for NT version 6.61 SP2a Computer Associates ARCserve 2000 version 7.0
Description The issue allows local and remote attackers to gain privileges by accessing the backup agent user name and password stored in cleartext in the aremote.dmp file located in the ARCSERVE$ hidden share.
Recommendations For Computer Associates ARCserve for NT version 6.61 SP2a, consider restricting access to the ARCSERVE$ hidden share to minimize the risk of exploitation. For Computer Associates ARCserve 2000 version 7.0, avoid using the affected backup agent until a secure method of storing user credentials is implemented. As a temporary workaround, consider disabling the backup agent functionality until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0960

Produtos afetados

Arcserve 2000
Arcserve For Nt