CVE-2006-6076
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC r...
Affects 3 products across 2 vendors.
A critical buffer overflow vulnerability exists in the Tape Engine (tapeeng.exe) of CA BrightStor ARCserve Backup 11.5 and earlier versions, allowing remote attackers to execute arbitrary code through specific RPC requests to TCP port 6502.
BSID: BS-2006-GLOBAL-172033-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2006-6076?
What is the CVSS score for CVE-2006-6076?
Is CVE-2006-6076 actively exploited?
How do I remediate CVE-2006-6076?
What systems are affected by CVE-2006-6076?
| CVE ID | CVE-2006-6076 |
|---|---|
| BSID | BS-2006-GLOBAL-172033-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2006-11-24 |
| Last Modified | 2026-04-23 |
| ICS Relevance | 0% |
| Source | NVD |
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502.
Source: NIST NVD / MITRE CVE Database
The vulnerability is triggered by sending specially crafted RPC requests to the Tape Engine service on TCP port 6502. This can lead to a buffer overflow, enabling an attacker to execute arbitrary code with the privileges of the service.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Broadcom | Brightstor Arcserve Backup | — |
| Ca | Brightstor Arcserve Backup | — |
| Ca | Brightstor Arcserve Backup Agent | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →