CVE-2023-26258: Critical severity arcserve unified data protection vulnerability
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26258?
CVE-2023-26258 is a vulnerability in Arcserve UDP through 9.0.6034 that allows authentication bypass, leading to remote code execution.
How severe is CVE-2023-26258?
CVE-2023-26258 has a severity rating of 9.8, which is considered critical.
How can I exploit CVE-2023-26258?
Exploiting CVE-2023-26258 requires obtaining the leaked AuthUUID token from the getVersionInfo method and using it to obtain a valid session, which can then be used to execute arbitrary code.
Is there a fix for CVE-2023-26258?
Yes, Arcserve has released a fix for CVE-2023-26258. It is recommended to update to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-26258?
You can find more information about CVE-2023-26258 on the Arcserve support website and the official Arcserve UDP product page.