← Vulnerability feed

Vulnerability record · CVE-2006-5143 · published 10 October 2006

CVE-2006-5143: CA BrightStor ARCserve Backup RPC services buffer overflow

Broadcom · Brightstor Arcserve Backup

Multiple buffer overflows exist in CA BrightStor ARCserve Backup and related products, affecting the Backup Agent RPC Server, Message Engine RPC Server, Discovery Service, and Job Engine Service. Crafted data sent to several TCP ports can overflow buffers and allow remote code execution, making this a serious pre-authentication risk for exposed backup infrastructure.

7.5 CVSS 2.0 High EPSS 80% · top 0.4% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
54References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with opcode (4) 0x2b or (5) 0x2d in ASCORE.dll in the Message Engine RPC Server (msgeng.exe); (6) a long hostname on TCP port 41523 to ASBRDCST.DLL in the Discovery Service (casdscsvc.exe); or unspecified vectors related to the (7) Job Engine Service.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution across multiple services on backup infrastructure, combined with a very high EPSS score and public exploit-related advisories, makes this an urgent patching priority.

What it is

Multiple buffer overflows exist in CA BrightStor ARCserve Backup and related products, affecting the Backup Agent RPC Server, Message Engine RPC Server, Discovery Service, and Job Engine Service. Crafted data sent to several TCP ports can overflow buffers and allow remote code execution, making this a serious pre-authentication risk for exposed backup infrastructure.

Impact

A remote attacker can execute arbitrary code with the privileges of the affected services, which typically run with high system rights on backup servers. This can lead to full compromise of the backup host and any data or credentials it manages.

Attack surface

The flaws are reachable over the network via TCP ports 6071, 6503, and 41523, plus unspecified vectors in the Job Engine Service. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.795 (99.6th percentile), and multiple public advisories and ZDI reports exist, indicating significant exploitation likelihood.

What to do

  • Apply the vendor patch referenced in the CA support notice and TippingPoint/ZDI advisories, upgrading to a fixed BrightStor ARCserve Backup release.
  • Restrict network access to TCP ports 6071, 6503, and 41523 so only trusted management hosts can reach the backup services.
  • Segment backup servers from general user networks and the internet, and block these ports at perimeter and internal firewalls.
  • Retire or isolate end-of-life versions such as r11.5 SP1, r11.1, 9.01, and Enterprise Backup 10.5 that no longer receive vendor support.
  • Monitor and limit access to the Job Engine Service and other RPC endpoints to trusted administrative subnets.

Detection

  • Monitor network traffic to TCP ports 6071, 6503, and 41523 for anomalous or oversized RPC payloads and unexpected source addresses.
  • Alert on crashes or restarts of DBASVR.exe, msgeng.exe, casdscsvc.exe, and Job Engine Service processes, which may indicate exploitation attempts.
  • Review service and application logs for malformed RPC opcodes such as 0x01, 0x02, 0x18, 0x2b, and 0x2d, and for unusually long hostname values reaching the Discovery Service.
  • Use IDS/IPS signatures for known BrightStor ARCserve RPC overflow attempts and correlate with outbound connections from backup servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/22285 Vendor Advisory
http://securitytracker.com/id?1017003
http://securitytracker.com/id?1017004
http://securitytracker.com/id?1017005
http://securitytracker.com/id?1017006
http://supportconnectw.ca.com/public/storage/infodocs/basbr-secnotice.asp Patch
http://www.kb.cert.org/vuls/id/361792 US Government Resource
http://www.kb.cert.org/vuls/id/860048 US Government Resource
http://www.lssec.com/advisories/LS-20060220.pdf
http://www.lssec.com/advisories/LS-20060313.pdf
http://www.lssec.com/advisories/LS-20060330.pdf
http://www.securityfocus.com/archive/1/447839/100/100/threaded
http://www.securityfocus.com/archive/1/447847/100/200/threaded
http://www.securityfocus.com/archive/1/447848/100/100/threaded
http://www.securityfocus.com/archive/1/447862/100/100/threaded
http://www.securityfocus.com/archive/1/447926/100/200/threaded
http://www.securityfocus.com/archive/1/447927/100/200/threaded
http://www.securityfocus.com/archive/1/447930/100/200/threaded
http://www.securityfocus.com/bid/20365
http://www.tippingpoint.com/security/advisories/TSRT-06-11.html Patch
http://www.vupen.com/english/advisories/2006/3930 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-030.html PatchVendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-031.html Vendor Advisory
http://www3.ca.com/securityadvisor/blogs/posting.aspx?pid=93775&id=90744
http://www3.ca.com/securityadvisor/blogs/posting.aspx?pid=94397&id=90744
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34693
https://exchange.xforce.ibmcloud.com/vulnerabilities/29364
http://secunia.com/advisories/22285 Vendor Advisory
http://securitytracker.com/id?1017003
http://securitytracker.com/id?1017004
http://securitytracker.com/id?1017005
http://securitytracker.com/id?1017006
http://supportconnectw.ca.com/public/storage/infodocs/basbr-secnotice.asp Patch
http://www.kb.cert.org/vuls/id/361792 US Government Resource
http://www.kb.cert.org/vuls/id/860048 US Government Resource
http://www.lssec.com/advisories/LS-20060220.pdf
http://www.lssec.com/advisories/LS-20060313.pdf
http://www.lssec.com/advisories/LS-20060330.pdf
http://www.securityfocus.com/archive/1/447839/100/100/threaded
http://www.securityfocus.com/archive/1/447847/100/200/threaded

Track CVE-2006-5143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4397CA ARCserve Backup RPC interface directory traversal enables remote command executionThe RPC interface exposed by asdbapi.dll in CA ARCserve Backup r11.1 through r12.0 fails to validate path input, allowing a .. (dot dot) sequence in …EPSS 81%analysed10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-2241Broadcom brightstor arcserve backup path traversal vulnerabilityDirectory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data…EPSS 12%10.0CVE-2007-5325Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) the Message Engine and (2) AScore.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r1…EPSS 12%10.0CVE-2007-5326Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityMultiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote…EPSS 12%10.0CVE-2007-5327Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityStack-based buffer overflow in the RPC interface for the Message Engine (mediasvr.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Ente…EPSS 16%10.0CVE-2007-5328Broadcom brightstor arcserve backup permissions and access controls vulnerabilityThe Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…EPSS 7.0%10.0CVE-2007-5329Broadcom brightstor arcserve backup vulnerabilityUnspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack …EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2006-5143), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.