CVE-2024-0800: Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
Published Mar 13, 2024
·Updated
A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.
Affected Software
3 affected components
Arcserve Unified Data Protection>=8.1<=9.2
Arcserve UDP=8.1
Arcserve UDP=9.2
Event History
Mar 13, 2024
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
May 14, 2024
News Published
via The Register·09:29 AM
News Published
via The Register·09:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-0800?
CVE-2024-0800 is classified as a critical severity vulnerability due to its potential to allow unauthorized file access.
2
How do I fix CVE-2024-0800?
To mitigate CVE-2024-0800, ensure that you upgrade Arcserve Unified Data Protection to version 9.3 or later.
3
What types of software are affected by CVE-2024-0800?
CVE-2024-0800 affects Arcserve Unified Data Protection versions 8.1 and 9.2.
4
What does CVE-2024-0800 vulnerability allow an attacker to do?
CVE-2024-0800 enables an attacker to perform path traversal attacks, potentially leading to unauthorized file access.
5
When was CVE-2024-0800 disclosed?
CVE-2024-0800 was disclosed in early 2024.