A critical vulnerability exists in Arcserve Unified Data Protection (UDP) that could allow a remote attacker to cause a denial of service or potentially enable arbitrary code execution. This heap-based buffer overflow flaw is reachable without authentication and affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported a [truncated]
CVE-2015-4068 is a directory traversal vulnerability in Arcserve Unified Data Protection (UDP). CISA added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an actively risk-relevant issue and prioritize remediation using vendor guidance.