LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-4068: Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-4068 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a denial of service.

CVE-2015-4068 is a directory traversal vulnerability in Arcserve Unified Data Protection (UDP). It allows remote attackers to obtain sensitive information or cause a denial of service. For IT and security teams, this matters because backup and recovery platforms often hold privileged access to critical data stores; a flaw of this class can expose configuration files, credentials, or other sensitive material, or disrupt availability of the backup service itself.

Public detail is limited to the CWE-22 classification and the high-level impact described by CISA. Confirm exact affected builds, attack prerequisites, and fixed releases against the vendor advisory before acting.

How it works

The weakness is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In products of this class, user-supplied input that influences file-system paths is not adequately sanitized. An attacker who can reach the vulnerable interface may craft path sequences (for example, using directory-ascent elements) that escape the intended directory and reach files or resources outside the authorized scope.

According to the CISA summary, successful abuse can let a remote attacker obtain sensitive information or trigger a denial of service. Specific request formats, authentication requirements, and exact reachable paths are not provided in the available facts; treat any public proof-of-concept claims cautiously and validate behavior only in a controlled lab against the vendor’s description.

Am I affected? How to find it in your systems

Arcserve UDP is typically deployed as a backup, disaster-recovery, or data-protection appliance or server, often on Windows hosts or dedicated virtual appliances inside data-center or branch networks. It may be reachable on management ports from administrative subnets or, if misconfigured, more broadly.

If your scanners do not yet fingerprint this CVE, treat any unpatched Arcserve UDP instance as potentially in scope until the vendor advisory confirms otherwise.

How to remediate

Patch first. Apply the updates supplied by Arcserve for Unified Data Protection exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; do not rely on third-party version guesses.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These steps lower risk but do not replace the official patch.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. Directory traversal that yields sensitive files may expose credentials, backup catalogs, or configuration data that enable further compromise. Known ransomware use of this CVE is not documented in the supplied facts; still treat any confirmed exploitation as a potential incident. Rotate credentials that may have resided on the affected system, review backup integrity, and examine logs for lateral movement. You can run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArcserve · Unified Data Protection (UDP)
WeaknessCWE-22
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities