CVE-2005-2535
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 81%
from disclosure to weapon0 days
Published on NVDAug 10
1st PoCFeb 12
metasploitFeb 14
exploitation probability
81%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/815unverifiedexploitdbwww.exploit-db.com/exploits/16408unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/bugtraq/2005-02/0123.htmlhttp://archives.neohapsis.com/archives/bugtraq/2005-02/0141.htmlhttp://archives.neohapsis.com/archives/bugtraq/2005-02/0201.htmlhttp://secunia.com/advisories/14293https://exchange.xforce.ibmcloud.com/vulnerabilities/19320http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?ID=32478http://www.kb.cert.org/vuls/id/966880http://www.osvdb.org/13814http://www.securityfocus.com/bid/12536