peter bassill · operator
$ cve CVE-2007-2139 JSON

CVE-2007-2139 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 78% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS78% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2007-04-25
Last modified2026-06-16

Affected (5)

VendorProduct
broadcombrightstor arcserve backup
broadcombusiness protection suite
broadcomserver protection suite
cabrightstor arcserve backup
cabusiness protection suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD