Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Brightstor_arcserve_backup_laptops_desktops | Broadcom | 4.0 (including) | 4.0 (including) |
Brightstor_arcserve_backup_laptops_desktops | Broadcom | 11.0 (including) | 11.0 (including) |
Brightstor_arcserve_backup_laptops_desktops | Broadcom | 11.1 (including) | 11.1 (including) |
Brightstor_arcserve_backup_laptops_desktops | Broadcom | 11.1-sp1 (including) | 11.1-sp1 (including) |
Brightstor_arcserve_backup_laptops_desktops | Broadcom | 11.5 (including) | 11.5 (including) |
Desktop_management_suite | Broadcom | 11.0 (including) | 11.0 (including) |
Desktop_management_suite | Broadcom | 11.1 (including) | 11.1 (including) |
Desktop_management_suite | Broadcom | 11.2 (including) | 11.2 (including) |
Protection_suites | Ca | r2 (including) | r2 (including) |