PatchSiren

Arcserve CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Arcserve CVE published 2025-08-27

CVE-2025-34523

A critical vulnerability exists in Arcserve Unified Data Protection (UDP) that could allow a remote attacker to cause a denial of service or potentially enable arbitrary code execution. This heap-based buffer overflow flaw is reachable without authentication and affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported a [truncated]

Known exploited Arcserve CVE published 2022-03-25

CVE-2015-4068

CVE-2015-4068 is a directory traversal vulnerability in Arcserve Unified Data Protection (UDP). CISA added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an actively risk-relevant issue and prioritize remediation using vendor guidance.