First published: Fri Feb 11 2005(Updated: )
The production release of the UniversalAgent for UNIX in BrightStor ARCserve Backup 11.1 contains hard-coded credentials, which allows remote attackers to access the file system and possibly execute arbitrary commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom ARCserve Backup | =11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0349 is considered a critical vulnerability due to its exploitation potential allowing remote access to the file system.
To fix CVE-2005-0349, update to a newer version of BrightStor ARCserve Backup that does not contain hard-coded credentials.
The risks associated with CVE-2005-0349 include unauthorized access to sensitive files and the potential execution of arbitrary commands on the affected system.
CVE-2005-0349 affects installations of BrightStor ARCserve Backup version 11.1 on UNIX systems.
CVE-2005-0349 is highly exploitable since the vulnerability involves hard-coded credentials that can be easily discovered and used by attackers.