PT-2012-4405 · Ca · Ca Arcserve Backup
Matteo Memelli
·
Published
2012-10-20
·
Updated
2021-04-07
·
CVE-2012-2972
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
CA ARCserve Backup versions r12.5 through r16
Description
The issue is related to the improper validation of RPC requests in the server and agent components, which can be exploited by remote attackers to cause a denial of service, resulting in a service crash, via a crafted request.
Recommendations
For CA ARCserve Backup versions r12.5 through r16, consider restricting access to the RPC service to minimize the risk of exploitation until a patch is available.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Arcserve Backup