CVE-2001-0960: Critical severity Broadcom Arcserve Backup vulnerability
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0960?
CVE-2001-0960 is classified as a high severity vulnerability due to the exposure of credentials in cleartext.
How do I fix CVE-2001-0960?
To fix CVE-2001-0960, it is recommended to upgrade to a patched version of ARCserve that does not store credentials in cleartext.
Who is affected by CVE-2001-0960?
Users of Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 are affected by CVE-2001-0960.
What kind of exploitation is possible with CVE-2001-0960?
CVE-2001-0960 can allow local and remote attackers to gain unauthorized privileges by accessing cleartext credentials.
Is CVE-2001-0960 still a relevant threat?
While CVE-2001-0960 is an older vulnerability, it remains a threat if outdated versions of ARCserve are still in use.