An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.
| Software | From | Fixed in |
|---|---|---|
| arcserve / udp | - | 9.2 |