Vulnerability record · CVE-2007-5082 · published 1 October 2007
CVE-2007-5082: CA BrightStor HSM CsAgent stack buffer overflow via opcode commands
Broadcom · Brightstor Hierarchical Storage Manager
CA BrightStor Hierarchical Storage Manager (HSM) before r11.6 contains multiple stack-based buffer overflows in the CsAgent service, caused by missing validation of a length parameter in certain commands. A remote, unauthenticated attacker can send crafted opcodes to the service and potentially execute arbitrary code on the host.
Description
Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands with certain opcodes, related to missing validation of a length parameter.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a complete impact rating, but no KEV listing or documented ransomware use is present.
What it is
CA BrightStor Hierarchical Storage Manager (HSM) before r11.6 contains multiple stack-based buffer overflows in the CsAgent service, caused by missing validation of a length parameter in certain commands. A remote, unauthenticated attacker can send crafted opcodes to the service and potentially execute arbitrary code on the host.
Impact
Successful exploitation allows remote code execution with the privileges of the CsAgent service, giving an attacker full control of the affected system. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
The flaw is reachable over the network through the CsAgent service (AV:N, AC:L, Au:N), so no authentication or user interaction is required. The description does not specify the exact port or protocol, only that certain CsAgent service commands with specific opcodes trigger the overflow.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high (0.6346, 99.17th percentile), indicating a meaningful probability of exploitation activity. Reference tags only indicate vendor advisories and patches, not public exploit code.
What to do
- Upgrade CA BrightStor HSM to r11.6 or later, which the vendor advisory identifies as the fixed release.
- If immediate upgrade is not possible, restrict network access to the CsAgent service to trusted management hosts only.
- Segment or firewall the HSM management network so the CsAgent service is not reachable from untrusted networks.
- Monitor vendor advisories for any updated patches or workarounds for this product line.
Detection
- Monitor network traffic to the CsAgent service for unusually long command payloads or malformed opcodes.
- Review service and application logs on HSM hosts for crashes, restarts or abnormal CsAgent behavior.
- Use host-based detection for unexpected process creation or code execution originating from the CsAgent service process.
- Track EPSS and vendor advisories for changes in exploitation likelihood or new patches.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-5082 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-5082), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.