iTnews Asia
  • Home
  • News
  • Software

Critical vulnerability discovered in Arcserve backup software

Critical vulnerability discovered in Arcserve backup software

Admin access leads to RCE.

By Richard Chirgwin on Jul 4, 2023 10:43AM

Arcserve has patched a critical authentication bypass in its Unified Data Protection product that gave attackers control over the software’s web administration interface, and led to a remote code execution (RCE) attack.

Discovered by researcher Juan Manuel Fernandez (@TheXC3LL) and MDSec’s Sean Doherty, CVE-2023-26258 affects UDP between version 7.0 and 9.0, and has been patched by Arcserve.

While exploring the login interactions between client and server, the two researchers spotted a variable called authUUID and method called validateUserByUuid.

They were then able to use that information to obtain access; as they described in this post, they got “a cookie with a session.”

From there, the researchers were then able to retrieve and decrypt the admin’s password, giving them complete control over the system, including RCE capabilities.

Fernandez and Doherty have posted their attack tools at GitHub.

According to the MDSec post, the pair first disclosed their findings to Arcserve on February 9, and the company posted its patch on June 27.

Arcserve said all UDP Windows agents and Recovery Point Servers need to be upgraded to 9.1, manually or via an automatic update.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
arcserve software

Related Articles

  • AI governance must evolve alongside adoption in APAC
  • 2026 a pivotal year for enterprises to deliver real value from AI
  • AI is triggering a structural reset in enterprise IT strategy
  • Vectorising the enterprise: Why 2026 is year of intelligent data platforms
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

2026 a pivotal year for enterprises to deliver real value from AI

2026 a pivotal year for enterprises to deliver real value from AI

AI is triggering a structural reset in enterprise IT strategy

AI is triggering a structural reset in enterprise IT strategy

Half of firms that cut customer service staff due to AI will rehire by 2027

Half of firms that cut customer service staff due to AI will rehire by 2027

Vectorising the enterprise: Why 2026 is year of intelligent data platforms

Vectorising the enterprise: Why 2026 is year of intelligent data platforms

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.