Vulnerability Description
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Arcserve Backup | 6.61 |
| Broadcom | Arcserve Backup 2000 | All versions |
| Ca | Arcserve Backup 2000 | All versions |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.htmlVendor Advisory
- http://support.ca.com/Download/patches/asitnt/QO00945.htmlPatch
- http://www.securityfocus.com/bid/3343PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7122
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0137.htmlVendor Advisory
- http://support.ca.com/Download/patches/asitnt/QO00945.htmlPatch
- http://www.securityfocus.com/bid/3343PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7122
FAQ
What is CVE-2001-0960?
CVE-2001-0960 is a vulnerability with a CVSS score of 10.0 (HIGH). Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows loca...
How severe is CVE-2001-0960?
CVE-2001-0960 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0960?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Arcserve Backup, Broadcom Arcserve Backup 2000, Ca Arcserve Backup 2000.