← Vulnerability feed

Vulnerability record · CVE-2005-1018 · published 2 May 2005

CVE-2005-1018: CA BrightStor ARCserve Backup UniversalAgent buffer overflow

CCa · Brightstor Arcserve Backup

The UniversalAgent in Computer Associates BrightStor ARCserve Backup contains a buffer overflow reachable over TCP port 6050 when an agent request supplies an oversized argument before the option field. A successful overflow can crash the agent or allow arbitrary code execution in its context.

7.5 CVSS 2.0 High EPSS 52% · top 1.1%
7.5CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable, can lead to code execution, and has a high EPSS score, though exploitation requires valid credentials and no KEV listing or confirmed public exploit is recorded.

What it is

The UniversalAgent in Computer Associates BrightStor ARCserve Backup contains a buffer overflow reachable over TCP port 6050 when an agent request supplies an oversized argument before the option field. A successful overflow can crash the agent or allow arbitrary code execution in its context.

Impact

An attacker can cause a denial of service against the backup agent or execute arbitrary code with the privileges of the UniversalAgent process, potentially compromising the backup server.

Attack surface

Reached remotely over the network via TCP port 6050 by sending a crafted agent request; the description states remote authenticated users, so valid credentials are required, and no user interaction is indicated.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded; EPSS shows a high 30-day probability (0.518, 98.9th percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.

What to do

  • Apply the vendor patch or upgrade to a fixed BrightStor ARCserve Backup release as soon as possible.
  • Restrict network access to TCP port 6050 to trusted backup hosts and management networks using firewall rules or ACLs.
  • Disable or stop the UniversalAgent service on systems that do not require it.
  • Enforce strong, unique credentials for agent access and monitor for unexpected authentication attempts.
  • Segment backup infrastructure from general user networks to limit lateral movement if the agent is compromised.

Detection

  • Monitor network traffic to TCP port 6050 for oversized or malformed agent requests, especially long argument fields before the option field.
  • Alert on UniversalAgent process crashes, restarts, or unexpected termination events on backup servers.
  • Review authentication logs for anomalous or repeated agent logins from unusual source hosts.
  • Use host-based detection for suspicious child processes or code execution spawned by the backup agent service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1018 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-2241Broadcom brightstor arcserve backup path traversal vulnerabilityDirectory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data…EPSS 12%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%10.0CVE-2007-5331Broadcom brightstor arcserve backup code injection vulnerabilityQueue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows re…EPSS 9.9%10.0CVE-2007-2863Broadcom anti-virus for the enterprise vulnerabilityStack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote …EPSS 23%10.0CVE-2007-2139CA BrightStor ARCserve Media Server SUN RPC stack buffer overflowThe SUN RPC service in CA BrightStor ARCserve Media Server contains multiple stack-based buffer overflows triggered by malformed RPC strings. The fla…EPSS 78%analysed10.0CVE-2006-6076CA BrightStor ARCserve Backup Tape Engine RPC buffer overflowThe Tape Engine (tapeeng.exe) in CA BrightStor ARCserve Backup 11.5 and earlier contains a buffer overflow reachable through certain RPC requests to …EPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2005-1018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.