← back
CVE-2008-4397

CVE-2008-4397

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 81%
from disclosure to weapon563 days
Published on NVDOct 14
1st PoC+563d
metasploitOct 9
exploitation probability
81%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.