← Vulnerability feed

Vulnerability record · CVE-2005-0491 · published 2 May 2005

CVE-2005-0491: Knox Arkeia Server Backup stack buffer overflow via type 77 request

Knox Software · Arkeia Server Backup

Knox Arkeia Server Backup 5.3.x contains a stack-based buffer overflow reachable through a long type 77 request. A remote, unauthenticated attacker can overwrite stack memory and execute arbitrary code on the backup server. Because backup servers hold broad access to protected data, compromise is severe.

10.0 CVSS 2.0 High EPSS 65% · top 0.8%
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityRemote unauthenticated code execution with CVSS 10.0 and high EPSS on an internet- or network-exposed backup server carrying sensitive data.

What it is

Knox Arkeia Server Backup 5.3.x contains a stack-based buffer overflow reachable through a long type 77 request. A remote, unauthenticated attacker can overwrite stack memory and execute arbitrary code on the backup server. Because backup servers hold broad access to protected data, compromise is severe.

Impact

Successful exploitation gives the attacker remote code execution with the privileges of the Arkeia service, typically root or SYSTEM, allowing full control of the backup server and the data it protects.

Attack surface

The flaw is reached over the network via the Arkeia service protocol by sending a crafted type 77 request; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

CVE-2005-0491 is not listed in CISA KEV, but EPSS is high at roughly 0.649 (99.2nd percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor patch referenced in the Secunia advisory (14327) or upgrade Arkeia Server Backup beyond the affected 5.3.x line.
  • Restrict network access to the Arkeia service port to trusted management hosts using firewall rules or ACLs.
  • Run the Arkeia service with least privilege where the product allows it, and isolate the backup server on a segmented management network.
  • Monitor vendor channels for a supported replacement if 5.3.x is end-of-life, since no further fixes may be issued.

Detection

  • Inspect Arkeia service logs for malformed or oversized type 77 requests and for service crashes or restarts.
  • Alert on unexpected child processes or shell activity spawned by the Arkeia service account.
  • Monitor network traffic to the Arkeia port for unusually large request payloads from untrusted sources.
  • Baseline normal Arkeia client IPs and alert on connections from hosts outside that set.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0491 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2005-0491), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.