Vulnerability record · CVE-2005-3190 · published 13 October 2005
CVE-2005-3190: CA iGateway debug mode buffer overflow allows remote code execution
Broadcom · Igateway
Computer Associates iGateway 3.0 and 4.0 before 4.0.050623 contains a buffer overflow that is reachable when the service runs in debug mode. A remote attacker can trigger it with crafted HTTP GET requests, making it a network-exposed flaw in an internet-facing gateway component.
Description
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows remote attackers to execute arbitrary code via HTTP GET requests.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a high EPSS score, tempered by the requirement that debug mode be enabled and the age of the affected releases.
What it is
Computer Associates iGateway 3.0 and 4.0 before 4.0.050623 contains a buffer overflow that is reachable when the service runs in debug mode. A remote attacker can trigger it with crafted HTTP GET requests, making it a network-exposed flaw in an internet-facing gateway component.
Impact
Successful exploitation allows arbitrary code execution under the privileges of the iGateway service, giving the attacker a foothold on the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached over the network via HTTP GET requests to the iGateway service, with no authentication required per the AV:N/AC:L/Au:N vector. The flaw only applies when the product is running in debug mode, so exposure depends on that non-default configuration.
Exploitation
Not listed in CISA KEV and no reference is tagged as an exploit, so confirmed in-the-wild exploitation is not established by this record. EPSS is high at 0.64816 (99.2nd percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Upgrade iGateway to 4.0.050623 or later, or to a currently supported release, per the vendor advisory.
- Disable debug mode on all iGateway instances; the overflow is only reachable in that mode.
- Restrict network access to the iGateway HTTP listener with firewall rules or a reverse proxy so only trusted sources can reach it.
- If the product is end-of-life and cannot be patched, isolate or retire the affected host.
- Monitor vendor advisories for Broadcom/CA iGateway since this CVE is old and the record may not reflect current support status.
Detection
- Search host and service inventories for iGateway 3.0 or 4.0 builds older than 4.0.050623 and confirm whether debug mode is enabled.
- Inspect HTTP access logs for unusually long or malformed GET requests to the iGateway listener that could indicate overflow attempts.
- Alert on iGateway process crashes or restarts, which can accompany memory corruption exploitation.
- Monitor for unexpected child processes or outbound connections originating from the iGateway service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-3190 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-3190), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.