Vulnerability record · CVE-2005-0491 · published 2 May 2005
CVE-2005-0491: Knox Arkeia Server Backup stack buffer overflow via type 77 request
Knox Software · Arkeia Server Backup
Knox Arkeia Server Backup 5.3.x contains a stack-based buffer overflow reachable through a long type 77 request. A remote, unauthenticated attacker can overwrite stack memory and execute arbitrary code on the backup server. Because backup servers hold broad access to protected data, compromise is severe.
Description
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityRemote unauthenticated code execution with CVSS 10.0 and high EPSS on an internet- or network-exposed backup server carrying sensitive data.
What it is
Knox Arkeia Server Backup 5.3.x contains a stack-based buffer overflow reachable through a long type 77 request. A remote, unauthenticated attacker can overwrite stack memory and execute arbitrary code on the backup server. Because backup servers hold broad access to protected data, compromise is severe.
Impact
Successful exploitation gives the attacker remote code execution with the privileges of the Arkeia service, typically root or SYSTEM, allowing full control of the backup server and the data it protects.
Attack surface
The flaw is reached over the network via the Arkeia service protocol by sending a crafted type 77 request; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
CVE-2005-0491 is not listed in CISA KEV, but EPSS is high at roughly 0.649 (99.2nd percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor patch referenced in the Secunia advisory (14327) or upgrade Arkeia Server Backup beyond the affected 5.3.x line.
- Restrict network access to the Arkeia service port to trusted management hosts using firewall rules or ACLs.
- Run the Arkeia service with least privilege where the product allows it, and isolate the backup server on a segmented management network.
- Monitor vendor channels for a supported replacement if 5.3.x is end-of-life, since no further fixes may be issued.
Detection
- Inspect Arkeia service logs for malformed or oversized type 77 requests and for service crashes or restarts.
- Alert on unexpected child processes or shell activity spawned by the Arkeia service account.
- Monitor network traffic to the Arkeia port for unusually large request payloads from untrusted sources.
- Baseline normal Arkeia client IPs and alert on connections from hosts outside that set.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-0491 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-0491), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.