Vulnerability record · CVE-2005-2668 · published 23 August 2005
CVE-2005-2668: CA Message Queuing buffer overflows allow remote code execution
Broadcom · Advantage Data Transport
Computer Associates Message Queuing (CAM/CAFT) versions 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 contain multiple buffer overflows reachable by remote attackers. The specific vectors are not described in the record, but the flaw permits arbitrary code execution and affects a broad set of CA enterprise products that embed the component.
Description
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityNetwork-reachable, unauthenticated code execution with maximum CVSS impact and very high EPSS, though no confirmed in-the-wild exploitation is documented.
What it is
Computer Associates Message Queuing (CAM/CAFT) versions 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 contain multiple buffer overflows reachable by remote attackers. The specific vectors are not described in the record, but the flaw permits arbitrary code execution and affects a broad set of CA enterprise products that embed the component.
Impact
A remote attacker can execute arbitrary code with the privileges of the vulnerable service, leading to full compromise of confidentiality, integrity and availability.
Attack surface
The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The exact protocol or port is not stated in the record.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.75244, 99.5th percentile), indicating elevated likelihood of exploitation activity. Reference tags include Patch and Vendor Advisory, so fixes exist.
What to do
- Apply the vendor patches referenced in the CA security advisory (Build 220_13 for 1.07 and Build 29_13 for 1.11) or upgrade to a supported release.
- Isolate or restrict network access to CAM/CAFT listeners on affected hosts using firewall rules and segmentation.
- Inventory all listed CA products (BrightStor, eTrust, Unicenter, CleverPath, Advantage, AdviseIT) to find embedded CAM/CAFT instances.
- Retire or migrate end-of-life CA/Broadcom products that can no longer be patched.
- Monitor for anomalous process behavior or crashes in CAM/CAFT services that could indicate exploitation attempts.
Detection
- Search host and network logs for unexpected connections to CAM/CAFT service ports on affected systems.
- Monitor for crash or restart events in CAM/CAFT-related processes, which may accompany buffer overflow attempts.
- Alert on suspicious child processes spawned by CA services, a common post-exploitation indicator.
- Review firewall and IDS logs for scanning or exploit traffic targeting CA management components.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://secunia.com/advisories/16513 | Third Party Advisory |
| http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp | Broken Link |
| http://www.kb.cert.org/vuls/id/619988 | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/18916 | Broken Link |
| http://www.securityfocus.com/bid/14622 | PatchThird Party AdvisoryVDB Entry |
| http://www.vupen.com/english/advisories/2005/1482 | Third Party Advisory |
| http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32919 | PatchVendor Advisory |
| http://secunia.com/advisories/16513 | Third Party Advisory |
| http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp | Broken Link |
| http://www.kb.cert.org/vuls/id/619988 | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/18916 | Broken Link |
| http://www.securityfocus.com/bid/14622 | PatchThird Party AdvisoryVDB Entry |
| http://www.vupen.com/english/advisories/2005/1482 | Third Party Advisory |
| http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32919 | PatchVendor Advisory |
Track CVE-2005-2668 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2668), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.