Vulnerability record · CVE-2005-0260 · published 2 May 2005
CVE-2005-0260: BrightStor ARCserve Backup Discovery Service UDP buffer overflow
Broadcom · Brightstor Arcserve Backup
The Discovery Service in BrightStor ARCserve Backup 11.1 and earlier has a stack-based buffer overflow because a long packet received on UDP port 41524 is not properly handled in a recvfrom call. A remote, unauthenticated attacker can send a crafted packet to trigger the overflow and potentially execute arbitrary code on the backup server.
Description
Stack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute arbitrary code via a long packet to UDP port 41524, which is not properly handled in a recvfrom call.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with remote, unauthenticated code execution and a high EPSS percentile make this a top remediation priority despite the absence of KEV listing.
What it is
The Discovery Service in BrightStor ARCserve Backup 11.1 and earlier has a stack-based buffer overflow because a long packet received on UDP port 41524 is not properly handled in a recvfrom call. A remote, unauthenticated attacker can send a crafted packet to trigger the overflow and potentially execute arbitrary code on the backup server.
Impact
Successful exploitation allows remote code execution with the privileges of the Discovery Service, giving an attacker full control of the affected host. Because the service handles backup infrastructure, compromise can expose stored backup data and other managed systems.
Attack surface
Reachable over the network via a single UDP packet to port 41524; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV, but EPSS is 0.69727 (99.3rd percentile) and a reference is tagged Exploit, indicating public exploit material exists and exploitation is plausible.
What to do
- Apply the vendor patch referenced in the CA support advisory for BrightStor ARCserve Backup.
- Upgrade to a supported ARCserve release if 11.1 or earlier cannot be patched.
- Block or restrict UDP port 41524 to trusted management hosts only.
- Segment backup servers from general user and internet-facing networks.
- Monitor for unsolicited UDP traffic to port 41524 on backup hosts.
Detection
- Alert on UDP packets to port 41524 containing unusually long or malformed payloads.
- Monitor for crashes or restarts of the ARCserve Discovery Service process.
- Watch for unexpected child processes or outbound connections originating from the backup server after Discovery Service activity.
- Review network flow logs for scanning or anomalous traffic toward UDP 41524 across the estate.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0260 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-0260), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.