CVE-2023-41998: Arcserve UDP Unauthenticated RCE
Published Nov 27, 2023
·Updated
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
Affected Software
1 affected component
Arcserve UDP<9.2
Event History
Nov 27, 2023
CVE Published
04:50 PM
Data Sourced
04:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-41998?
CVE-2023-41998 is a vulnerability in Arcserve UDP that allows an attacker to upload and execute arbitrary files.
2
What is the severity of CVE-2023-41998?
CVE-2023-41998 has a severity rating of critical with a score of 9.8.
3
How does CVE-2023-41998 affect Arcserve UDP?
CVE-2023-41998 affects Arcserve UDP versions prior to 9.2.
4
How can an attacker exploit CVE-2023-41998?
An attacker can exploit CVE-2023-41998 by uploading and executing arbitrary files.
5
Is there a fix available for CVE-2023-41998?
Yes, a fix for CVE-2023-41998 is available by updating to version 9.2 or later of Arcserve UDP.