CVE-2006-5143
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with opcode (4) 0x2b or (5) 0x2d in ASCORE.dll in the Message Engine RPC Server (msgeng.exe); (6) a long hostname on TCP port 41523 to ASBRDCST.DLL in the Discovery Service (casdscsvc.exe); or unspecified vectors related to the (7) Job Engine Service.
Published:Oct 6, 2006
Last Modified:Apr 23, 2026
EPS:Oct 6, 2006
EPSS Score:0.84629
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Broadcom
Product
Brightstor Arcserve Backup
Broadcom
Brightstor Arcserve Backup
Vendor
Broadcom
Product
Brightstor Enterprise Backup
Broadcom
Brightstor Enterprise Backup
Vendor
Broadcom
Product
Business Protection Suite
Broadcom
Business Protection Suite
Vendor
Broadcom
Product
Server Protection Suite
Broadcom
Server Protection Suite
Vendor
Ca
Product
Brightstor Arcserve Backup
Ca
Brightstor Arcserve Backup
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
