Skip to content
COOEY

EXPOSURES › CVE-2015-4068

CVE-2015-4068

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2015-4068 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Arcserve UDP suffered a directory traversal vulnerability allowing remote attackers to steal data or cause denial of service.

Arcserve Unified Data Protection (UDP) contained a directory traversal flaw enabling remote attackers to access sensitive files or disrupt service. DIB organizations must ensure backup and recovery software is patched, as unpatched vulnerabilities in critical infrastructure can lead to data exfiltration or ransomware footholds. This failure highlights the risk of relying on legacy or unpatched enterprise software.

Shame score — A known directory traversal vulnerability in critical backup software was actively exploited in the wild, indicating a failure to patch a high-impact flaw in time.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.