QID 378714
Date Published: 2023-08-07
QID 378714: Arcserve UDP Remote Code Execution (RCE) Vulnerability
Arcserve Unified Data Protection (UDP) software delivers an all-in-one data and ransomware protection solution to neutralize ransomware attacks, restore data, and perform effective disaster recovery (DR).
CVE-2023-26258: Arcserve UDP is vulnerable to authentication bypass vulnerability that could lead to remote code execution.
Affected Versions:
Arcserve UDP versions from 7.0.0.0 prior to 9.0.6034.294 (9.1).
Patched Versions:
Arcserve UDP version 7.0.4455.634 (7.0 u2) with Fix Number P00002855
Arcserve UDP version 8.0.5628.430 (8.1) with Fix Number P00002856
Arcserve UDP prior version 9.0.6034.294 (9.1) with Fix Number P00002847
QID Detection Logic:
Authenticated: This QID checks for installed version of Arcserve UDP using "ARCUpdate.exe" and installed patches from location "APM\PatchHistory.xml"
Unauthenticated: This QID retrieves the AuthUUID and later use it to obtain SessionID which further used to retrieve the username and encrypted password.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary code on the target system.
- Arcserve UDP Security Advisory -
support.arcserve.com/s/article/KB000015720?language=en_US
CVEs related to QID 378714
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Arcserve UDP Security Advisory |
|