Where
-Infinity
0
Severity
8.9
Path Traversal
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks.

An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim’s machine).

Remedy

Upgrade to v1.6.0 or later.
First published (updated )
Severity
7.3
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges.

By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.

Remedy

Upgrade to v1.6.0 or later.
First published (updated )
Severity
7.3
AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself.

A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.

Remedy

Upgrade to v1.6.0 or later.
First published (updated )
Severity
6.5
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

The server certificate was not verified when an Arc agent connected to a Guardian or CMC.

A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result in theft of the client token and sensitive information (such as assets and alerts), impersonation of the server, or injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC.

Remedy

Upgrade Arc to v2.2.0 or later.
First published (updated )
Severity
5.2
AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

On Windows systems, the Arc configuration files resulted to be world-readable.

This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.

Remedy

Upgrade to v1.6.0 or later.
First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203