peter bassill · operator
$ cve CVE-2008-4397 JSON

CVE-2008-4397 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 80.5% (pctl 100)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS80.54% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-10-14
Last modified2026-06-16

Affected (5)

VendorProduct
broadcomarcserve backup
broadcombusiness protection suite
broadcomserver protection suite
caarcserve backup
cabusiness protection suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD