VendorsArcserveudpall versions
Vulnerabilities

Arcserve UDP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-26258
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
Published 2023-07-03 · Modified
9.8EPSS 0.398
CVE-2023-41998
Arcserve UDP Unauthenticated RCE
Published 2023-11-27 · Modified
9.8EPSS 0.153
CVE-2024-0799
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
Published 2024-03-13 · Analyzed
9.8EPSS 0.043
CVE-2023-42000
Arcserve UDP Agent Unauthenticated Path Traversal File Upload
Published 2023-11-27 · Modified
9.8EPSS 0.015
CVE-2023-41999
Arcserve UDP Management Authentication Bypass
Published 2023-11-27 · Modified
9.8EPSS 0.014
CVE-2025-34522
Arcserve UDP < 10.2 Pre-Authentication Heap Overflow
Published 2025-08-27 · Analyzed
9.8EPSS 0.006
CVE-2025-34523
Arcserve UDP < 10.2 Pre-Authentication Heap Overflow
Published 2025-08-27 · Modified
9.8EPSS 0.005
CVE-2025-34520
Arcserve UDP < 10.2 Authentication Bypass
Published 2025-08-27 · Analyzed
9.8EPSS 0.004
CVE-2015-4068
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
Published 2015-05-29 · Analyzed
9.4KEVEPSS 0.636
CVE-2024-0800
Authentication Bypass via wizardLogin in Arcserve Unified Data Protection
Published 2024-03-13 · Analyzed
8.8EPSS 0.010
CVE-2024-0801
Unauthenticated DoS in Arcserve Unified Data Protection
Published 2024-03-13 · Analyzed
7.5EPSS 0.418
CVE-2018-18659
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue.
Published 2018-10-26 · Modified
7.5EPSS 0.018
CVE-2018-18657
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-18 Unauthenticated Sensitive Information Disclosure via /gateway/services/EdgeServiceImpl issue.
Published 2018-10-26 · Modified
7.5EPSS 0.013
CVE-2018-18658
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-20 Unauthenticated Sensitive Information Disclosure via /UDPUpdates/Config/FullUpdateSettings.xml issue.
Published 2018-10-26 · Modified
7.5EPSS 0.013
CVE-2018-18660
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domain.jsp issue.
Published 2018-10-26 · Modified
6.1EPSS 0.009
CVE-2025-34521
Arcserve UDP < 10.2 Reflected Cross-Site Scripting (XSS)
Published 2025-08-27 · Analyzed
5.4EPSS 0.002