UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Arcserve
Arcserve udp Console
Vendors & Products Arcserve
Arcserve udp Console

Thu, 16 Apr 2026 09:15:00 +0000

Type Values Removed Values Added
Title Incorrect Destination Specification Leading to Unintended Communication and Information Disclosure in Arcserve UDP Console

Thu, 16 Apr 2026 05:00:00 +0000

Type Values Removed Values Added
Description UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information disclosure.
Weaknesses CWE-941
References
Metrics cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-04-16T13:00:56.282Z

Reserved: 2026-04-09T04:39:51.927Z

Link: CVE-2026-40118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-16T05:16:14.860

Modified: 2026-04-16T05:16:14.860

Link: CVE-2026-40118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T09:11:54Z

Weaknesses