CVE-2024-0800: Arcserve UDP

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.

Affected products

  • Arcserve UDP: version 8.1 only; version 9.2 only

Published 2024-03-13. Last modified 2026-06-17.