← Vulnerability feed

Vulnerability record · CVE-2007-5005 · published 1 October 2007

CVE-2007-5005: Broadcom brightstor arcserve backup laptops desktops path traversal vulnerability

Broadcom · Brightstor Arcserve Backup Laptops Desktops

Directory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to upload and overwrite arbitrary files via a ..\ (dot dot backslash) sequence in the destination filename argument to sub-function 8 in the rxrReceiveFileFromServer command.

10.0 CVSS 2.0 High EPSS 5.2% · top 7.8% CWE-22 · Path traversal
10.0CVSS 2.0 base score
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in rxRPC.dll in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 allows remote attackers to upload and overwrite arbitrary files via a ..\ (dot dot backslash) sequence in the destination filename argument to sub-function 8 in the rxrReceiveFileFromServer command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5005 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0042Broadcom anti-spyware vulnerabilityMultiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterpr…EPSS 4.3%10.0CVE-2008-3175Broadcom brightstor arcserve backup vulnerabilityInteger underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…EPSS 14%10.0CVE-2008-1329Broadcom desktop management suite vulnerabilityUnspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allow…EPSS 5.9%10.0CVE-2007-5003CA BrightStor ARCserve Backup for Laptops and Desktops stack buffer overflowMultiple stack-based buffer overflows exist in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5. A remote attacker can send…EPSS 67%analysed10.0CVE-2007-5006Broadcom brightstor arcserve backup laptops desktops improper authentication vulnerabilityMultiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer…EPSS 21%10.0CVE-2007-3216CA BrightStor ARCserve LGServer buffer overflows allow remote code executionThe LGServer component of CA BrightStor ARCserve Backup for Laptops and Desktops r11.1 contains multiple buffer overflows reachable through crafted a…EPSS 59%analysed10.0CVE-2007-0449CA BrightStor ARCserve LGSERVER.EXE remote buffer overflowLGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops (and related CA products) contains multiple buffer overflows reachable via cra…EPSS 79%analysed10.0CVE-2006-5171Broadcom brightstor arcserve backup vulnerabilityStack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2007-5005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.