CVE-2023-41998: Arcserve UDP
Critical severity, CVSS 9.8. EPSS: 15.3% chance of exploitation in the next 30 days.
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
Affected products
- Arcserve UDP: before 9.2 (fixed in 9.2)
Published 2023-11-27. Last modified 2026-06-17.