CVE-2006-6076
Summary
| CVE | CVE-2006-6076 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-11-24 17:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Broadcom | Brightstor Arcserve Backup | 11.1 | All | All | All |
| Application | Broadcom | Brightstor Arcserve Backup | 11.5 | sp1 | All | All |
| Application | Broadcom | Brightstor Arcserve Backup | All | All | All | All |
| Application | Ca | Brightstor Arcserve Backup | 11 | All | windows | All |
| Application | Ca | Brightstor Arcserve Backup | 11.1 | All | windows | All |
| Application | Ca | Brightstor Arcserve Backup Agent | 11.0 | All | sql | All |
| Application | Ca | Brightstor Arcserve Backup Agent | 11.1 | All | sql | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Computer Associates BrightStor ARCserve Backup Tape Engine Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [Full-disclosure] LS-20061113 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| supportconnectw.ca.com/public/storage/infodocs/babtapeng-securitynotice.asp | af854a3a-2127-422b-91ae-364da2661108 | supportconnectw.ca.com | |
| CA BrightStor ARCserve Backup Tape Engine buffer overflow vulnerability - CA | af854a3a-2127-422b-91ae-364da2661108 | www3.ca.com | |
| US-CERT Vulnerability Note VU#437300 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| [Full-disclosure] LS-20061113 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CA BrightStor ARCserve Backup Tape Engine and Portmapper Vulnerabilities - CA | af854a3a-2127-422b-91ae-364da2661108 | www3.ca.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CA BrightStor ARCserve Backup Buffer Overflow Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| BrightStor ARCserve Tape Engine Buffer Overflow Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CA BrightStor ARCserve Backup Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.