First published: Sat Sep 15 2001(Updated: )
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom BrightStor ARCserve Backup | =6.61-sp2a | |
CA BrightStor ARCserve Backup | ||
Broadcom BrightStor ARCServe Backup |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0960 is classified as a high severity vulnerability due to the exposure of credentials in cleartext.
To fix CVE-2001-0960, it is recommended to upgrade to a patched version of ARCserve that does not store credentials in cleartext.
Users of Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 are affected by CVE-2001-0960.
CVE-2001-0960 can allow local and remote attackers to gain unauthorized privileges by accessing cleartext credentials.
While CVE-2001-0960 is an older vulnerability, it remains a threat if outdated versions of ARCserve are still in use.