CVE-2023-42000: Arcserve UDP

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

Affected products

Published 2023-11-27. Last modified 2026-06-17.