First published: Thu Jan 11 2007(Updated: )
The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an RPC request, which is directly executed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom ARCserve Backup | <=11.5 | |
Broadcom ARCserve Backup | =9.01 | |
Broadcom BrightStor Enterprise Backup | =10.5 | |
Broadcom Business Protection Suite | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0168 is classified as a critical vulnerability due to its potential to allow remote code execution.
Mitigation for CVE-2007-0168 includes applying available patches from Broadcom for affected versions of BrightStor ARCserve Backup and related products.
CVE-2007-0168 affects Broadcom BrightStor ARCserve Backup versions 9.01 through 11.5, Enterprise Backup 10.5, and Business Protection Suite r2.
CVE-2007-0168 enables remote attackers to execute arbitrary code via specially crafted RPC requests.
While there have been reports of exploitation attempts, the overall active exploitation level of CVE-2007-0168 should be evaluated based on current threat intelligence.