← Vulnerability feed

Vulnerability record · CVE-2007-5082 · published 1 October 2007

CVE-2007-5082: CA BrightStor HSM CsAgent stack buffer overflow via opcode commands

Broadcom · Brightstor Hierarchical Storage Manager

CA BrightStor Hierarchical Storage Manager (HSM) before r11.6 contains multiple stack-based buffer overflows in the CsAgent service, caused by missing validation of a length parameter in certain commands. A remote, unauthenticated attacker can send crafted opcodes to the service and potentially execute arbitrary code on the host.

10.0 CVSS 2.0 High EPSS 63% · top 0.8% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary code via unspecified CsAgent service commands with certain opcodes, related to missing validation of a length parameter.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and has a complete impact rating, but no KEV listing or documented ransomware use is present.

What it is

CA BrightStor Hierarchical Storage Manager (HSM) before r11.6 contains multiple stack-based buffer overflows in the CsAgent service, caused by missing validation of a length parameter in certain commands. A remote, unauthenticated attacker can send crafted opcodes to the service and potentially execute arbitrary code on the host.

Impact

Successful exploitation allows remote code execution with the privileges of the CsAgent service, giving an attacker full control of the affected system. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

The flaw is reachable over the network through the CsAgent service (AV:N, AC:L, Au:N), so no authentication or user interaction is required. The description does not specify the exact port or protocol, only that certain CsAgent service commands with specific opcodes trigger the overflow.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high (0.6346, 99.17th percentile), indicating a meaningful probability of exploitation activity. Reference tags only indicate vendor advisories and patches, not public exploit code.

What to do

  • Upgrade CA BrightStor HSM to r11.6 or later, which the vendor advisory identifies as the fixed release.
  • If immediate upgrade is not possible, restrict network access to the CsAgent service to trusted management hosts only.
  • Segment or firewall the HSM management network so the CsAgent service is not reachable from untrusted networks.
  • Monitor vendor advisories for any updated patches or workarounds for this product line.

Detection

  • Monitor network traffic to the CsAgent service for unusually long command payloads or malformed opcodes.
  • Review service and application logs on HSM hosts for crashes, restarts or abnormal CsAgent behavior.
  • Use host-based detection for unexpected process creation or code execution originating from the CsAgent service process.
  • Track EPSS and vendor advisories for changes in exploitation likelihood or new patches.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-5083Broadcom brightstor hierarchical storage manager memory buffer overflow vulnerabilityMultiple integer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute a…EPSS 19%6.8CVE-2007-5084Broadcom brightstor hierarchical storage manager sql injection vulnerabilityMultiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers …EPSS 1.8%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEVEPSS 1.2%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2007-5082), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.