Vulnerability record · CVE-2006-5143 · published 10 October 2006
CVE-2006-5143: CA BrightStor ARCserve Backup RPC services buffer overflow
Broadcom · Brightstor Arcserve Backup
Multiple buffer overflows exist in CA BrightStor ARCserve Backup and related products, affecting the Backup Agent RPC Server, Message Engine RPC Server, Discovery Service, and Job Engine Service. Crafted data sent to several TCP ports can overflow buffers and allow remote code execution, making this a serious pre-authentication risk for exposed backup infrastructure.
Description
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with opcode (4) 0x2b or (5) 0x2d in ASCORE.dll in the Message Engine RPC Server (msgeng.exe); (6) a long hostname on TCP port 41523 to ASBRDCST.DLL in the Discovery Service (casdscsvc.exe); or unspecified vectors related to the (7) Job Engine Service.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution across multiple services on backup infrastructure, combined with a very high EPSS score and public exploit-related advisories, makes this an urgent patching priority.
What it is
Multiple buffer overflows exist in CA BrightStor ARCserve Backup and related products, affecting the Backup Agent RPC Server, Message Engine RPC Server, Discovery Service, and Job Engine Service. Crafted data sent to several TCP ports can overflow buffers and allow remote code execution, making this a serious pre-authentication risk for exposed backup infrastructure.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected services, which typically run with high system rights on backup servers. This can lead to full compromise of the backup host and any data or credentials it manages.
Attack surface
The flaws are reachable over the network via TCP ports 6071, 6503, and 41523, plus unspecified vectors in the Job Engine Service. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.795 (99.6th percentile), and multiple public advisories and ZDI reports exist, indicating significant exploitation likelihood.
What to do
- Apply the vendor patch referenced in the CA support notice and TippingPoint/ZDI advisories, upgrading to a fixed BrightStor ARCserve Backup release.
- Restrict network access to TCP ports 6071, 6503, and 41523 so only trusted management hosts can reach the backup services.
- Segment backup servers from general user networks and the internet, and block these ports at perimeter and internal firewalls.
- Retire or isolate end-of-life versions such as r11.5 SP1, r11.1, 9.01, and Enterprise Backup 10.5 that no longer receive vendor support.
- Monitor and limit access to the Job Engine Service and other RPC endpoints to trusted administrative subnets.
Detection
- Monitor network traffic to TCP ports 6071, 6503, and 41523 for anomalous or oversized RPC payloads and unexpected source addresses.
- Alert on crashes or restarts of DBASVR.exe, msgeng.exe, casdscsvc.exe, and Job Engine Service processes, which may indicate exploitation attempts.
- Review service and application logs for malformed RPC opcodes such as 0x01, 0x02, 0x18, 0x2b, and 0x2d, and for unusually long hostname values reaching the Discovery Service.
- Use IDS/IPS signatures for known BrightStor ARCserve RPC overflow attempts and correlate with outbound connections from backup servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5143 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5143), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.