← Vulnerability feed

Vulnerability record · CVE-2024-0799 · published 13 March 2024

CVE-2024-0799: Arcserve udp improper authentication vulnerability

Arcserve · Udp

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

9.8 CVSS 3.1 Critical EPSS 4.3% · top 9.1% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-0799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2015-4068Arcserve UDP servlet path traversal exposes files and causes DoSArcserve UDP before 5.0 Update 4 contains a directory traversal flaw in the reportFileServlet and exportServlet servlets. A crafted file path lets a …KEVEPSS 64%analysed9.8CVE-2023-42000Arcserve udp path traversal vulnerabilityArcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthentic…EPSS 1.5%9.8CVE-2023-41998Arcserve udp unrestricted file upload vulnerabilityArcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows …EPSS 15%9.8CVE-2023-41999Arcserve udp improper authentication vulnerabilityAn authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifie…EPSS 1.4%9.8CVE-2023-26258Arcserve udp incorrect authorization vulnerabilityArcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID …EPSS 40%9.2CVE-2025-34522Arcserve udp heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered wi…EPSS 0.56%9.2CVE-2025-34523Arcserve udp heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw …EPSS 0.53%8.8CVE-2024-0800Arcserve udp unrestricted file upload vulnerabilityA path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.ser…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2024-0799), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.