← Vulnerability feed

Vulnerability record · CVE-2005-1272 · published 5 August 2005

CVE-2005-1272: BrightStor ARCserve Backup Agent for SQL Server stack buffer overflow

Broadcom · Brightstor Enterprise Backup

The Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 contains a stack-based buffer overflow reachable by sending a long string to port 6070 or 6050. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the backup server.

7.5 CVSS 2.0 High EPSS 66% · top 0.7%
7.5CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication, has public exploit references, and carries a very high EPSS score, though it affects an old, likely retired product.

What it is

The Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 contains a stack-based buffer overflow reachable by sending a long string to port 6070 or 6050. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the backup server.

Impact

Successful exploitation allows remote code execution with the privileges of the vulnerable backup agent service, giving an attacker control of the host. Because the service runs on a backup server, compromise can also expose backed-up data and connected systems.

Attack surface

The flaw is reached over the network via TCP ports 6070 or 6050; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.66121, 99.24th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor patch referenced in the CA and CERT/CC advisories as soon as possible.
  • If patching is not immediately possible, block or restrict access to TCP ports 6070 and 6050 to trusted hosts only.
  • Isolate backup agent hosts on a management network separate from general user and internet-facing networks.
  • Retire or upgrade end-of-life BrightStor ARCserve Backup Agent for SQL Server 11.0, which no longer receives vendor support.
  • Monitor vendor advisories for any updated guidance affecting the affected agent.

Detection

  • Monitor network traffic to TCP ports 6070 and 6050 for unusually long or malformed strings targeting the backup agent.
  • Alert on unexpected process creation or crashes of the BrightStor ARCserve backup agent service on SQL Server hosts.
  • Review host logs for service restarts or abnormal termination of the backup agent following inbound connections on those ports.
  • Use IDS/IPS signatures for stack buffer overflow attempts against ARCserve backup agent services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1272 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-2241Broadcom brightstor arcserve backup path traversal vulnerabilityDirectory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data…EPSS 12%10.0CVE-2007-5325Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r1…EPSS 12%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5327Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityStack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Ente…EPSS 16%10.0CVE-2007-5328Broadcom brightstor arcserve backup permissions and access controls vulnerabilityThe Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…EPSS 7.0%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%10.0CVE-2007-5330Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityThe cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbit…EPSS 13%

Source: NIST National Vulnerability Database (record CVE-2005-1272), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.