CVE-2024-0799: Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
Published Mar 13, 2024
·Updated
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
Affected Software
3 affected components
Arcserve Unified Data Protection>=8.1<=9.2
Arcserve UDP=8.1
Arcserve UDP=9.2
Event History
Mar 13, 2024
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
May 14, 2024
News Published
via The Register·09:29 AM
News Published
via The Register·09:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-0799?
CVE-2024-0799 has been assessed as a critical vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2024-0799?
To fix CVE-2024-0799, update Arcserve Unified Data Protection to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-0799?
CVE-2024-0799 affects Arcserve Unified Data Protection versions 8.1 to 9.2.
4
What kind of attack can exploit CVE-2024-0799?
CVE-2024-0799 can be exploited to gain unauthorized access to the system due to its authentication bypass nature.
5
When was CVE-2024-0799 reported?
CVE-2024-0799 was reported in 2024, highlighting a significant security issue in the identified software.