CVE-2023-41998: Arcserve UDP

Critical severity, CVSS 9.8. EPSS: 15.3% chance of exploitation in the next 30 days.

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.

Affected products

Published 2023-11-27. Last modified 2026-06-17.