9.8
CVSSv3

CVE-2023-42000

Published: 27/11/2023 Updated: 10/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Arcserve UDP before 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arcserve udp