Vulnerability record · CVE-2005-1018 · published 2 May 2005
CVE-2005-1018: CA BrightStor ARCserve Backup UniversalAgent buffer overflow
CCa · Brightstor Arcserve Backup
The UniversalAgent in Computer Associates BrightStor ARCserve Backup contains a buffer overflow reachable over TCP port 6050 when an agent request supplies an oversized argument before the option field. A successful overflow can crash the agent or allow arbitrary code execution in its context.
Description
Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely reachable, can lead to code execution, and has a high EPSS score, though exploitation requires valid credentials and no KEV listing or confirmed public exploit is recorded.
What it is
The UniversalAgent in Computer Associates BrightStor ARCserve Backup contains a buffer overflow reachable over TCP port 6050 when an agent request supplies an oversized argument before the option field. A successful overflow can crash the agent or allow arbitrary code execution in its context.
Impact
An attacker can cause a denial of service against the backup agent or execute arbitrary code with the privileges of the UniversalAgent process, potentially compromising the backup server.
Attack surface
Reached remotely over the network via TCP port 6050 by sending a crafted agent request; the description states remote authenticated users, so valid credentials are required, and no user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded; EPSS shows a high 30-day probability (0.518, 98.9th percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.
What to do
- Apply the vendor patch or upgrade to a fixed BrightStor ARCserve Backup release as soon as possible.
- Restrict network access to TCP port 6050 to trusted backup hosts and management networks using firewall rules or ACLs.
- Disable or stop the UniversalAgent service on systems that do not require it.
- Enforce strong, unique credentials for agent access and monitor for unexpected authentication attempts.
- Segment backup infrastructure from general user networks to limit lateral movement if the agent is compromised.
Detection
- Monitor network traffic to TCP port 6050 for oversized or malformed agent requests, especially long argument fields before the option field.
- Alert on UniversalAgent process crashes, restarts, or unexpected termination events on backup servers.
- Review authentication logs for anomalous or repeated agent logins from unusual source hosts.
- Use host-based detection for suspicious child processes or code execution spawned by the backup agent service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1018 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.