VDB
CVE-2007-0168
CVE-2007-0168
PUBLISHED
CVSS 7.5 HIGH
The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.
EPSS 61.28% · 98.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
61.28%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| broadcom | brightstor_arcserve_backup | 0, 9.01 |
| n/a | n/a | n/a |
| broadcom | brightstor_enterprise_backup | 10.5 |
| broadcom | business_protection_suite | 2.0 |
Timeline
- Jan 11, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp url
- http://livesploit.com/advisories/LS-20061002.pdf url
- 22010 vdb
- brightstor-tapeengine-code-execution(31442) vdb
- 1017506 vdb
- http://www.zerodayinitiative.com/advisories/ZDI-07-002.html url
- 20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities mailing-list
- 20070111 LS-20061002 - Computer Associates BrightStor ARCserve Backup Remote Code Execution Vulnerability mailing-list
- ADV-2007-0154 vdb
- 31327 vdb
- VU#662400 third-party-advisory
- 20070111 ZDI-07-002: CA BrightStor ARCserve Backup Tape Engine Code Execution Vulnerability mailing-list
- http://www.lssec.com/advisories/LS-20061002.pdf url
- 23648 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-0168 advisory