Skip to main content

Vendor/product archive

arcserve / udp CVEs

Beta · best-effort

16 CVEs tagged to arcserve / udp8 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-34523

Published Aug 27, 2025

A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentic…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34522

Published Aug 27, 2025

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sendin…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34521

Published Aug 27, 2025

A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflecte…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34520

Published Aug 27, 2025

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user ac…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0801

Published Mar 13, 2024

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0800

Published Mar 13, 2024

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-0799

Published Mar 13, 2024

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-42000

Published Nov 27, 2023

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can explo…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-41999

Published Nov 27, 2023

An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenti…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-41998

Published Nov 27, 2023

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and exec…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-26258

Published Jul 3, 2023

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2018-18660

Published Oct 26, 2018

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domai…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18659

Published Oct 26, 2018

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18658

Published Oct 26, 2018

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18657

Published Oct 26, 2018

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Information Disclosure via /gateway/se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4068

Published May 29, 2015

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1