CVE-2005-3653

Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

Published: 2005-12-31 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2005-3653 is rated High Risk (68.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 30.44%, 96th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2005-3653

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-06-29 36.61% 30.44% -6.16%
2 2025-03-30 31.52% 36.61% +5.08%
3 2025-03-29 31.52%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2005-3653

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2005-3653

Affected software / configurations for CVE-2005-3653

Vendor Product Version Raw CPE
broadcom brightstor_arcserve_backup 9.01 cpe:2.3:a:broadcom:brightstor_arcserve_backup:9.01:*:*:*:*:*:*:*
broadcom brightstor_arcserve_backup 11.1 cpe:2.3:a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:*
broadcom brightstor_arcserve_backup 11.5 cpe:2.3:a:broadcom:brightstor_arcserve_backup:11.5:*:*:*:*:*:*:*
broadcom brightstor_arcserve_backup_laptops_desktops 11.0 cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*
broadcom brightstor_arcserve_backup_laptops_desktops 11.1 cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*
broadcom brightstor_portal 11.1 cpe:2.3:a:broadcom:brightstor_portal:11.1:*:*:*:*:*:*:*
broadcom brightstor_process_automation_manager 11.1 cpe:2.3:a:broadcom:brightstor_process_automation_manager:11.1:*:*:*:*:*:*:*
broadcom brightstor_san_manager 11.1 cpe:2.3:a:broadcom:brightstor_san_manager:11.1:*:*:*:*:*:*:*
broadcom brightstor_san_manager 11.5 cpe:2.3:a:broadcom:brightstor_san_manager:11.5:*:*:*:*:*:*:*
broadcom brightstor_storage_resource_manager 6.3 cpe:2.3:a:broadcom:brightstor_storage_resource_manager:6.3:*:*:*:*:*:*:*
broadcom brightstor_storage_resource_manager 6.4 cpe:2.3:a:broadcom:brightstor_storage_resource_manager:6.4:*:*:*:*:*:*:*
broadcom brightstor_storage_resource_manager 11.1 cpe:2.3:a:broadcom:brightstor_storage_resource_manager:11.1:*:*:*:*:*:*:*
broadcom brightstor_storage_resource_manager 11.5 cpe:2.3:a:broadcom:brightstor_storage_resource_manager:11.5:*:*:*:*:*:*:*
broadcom etrust_admin 8.1 cpe:2.3:a:broadcom:etrust_admin:8.1:*:*:*:*:*:*:*
broadcom etrust_audit_aries 8.0 cpe:2.3:a:broadcom:etrust_audit_aries:8.0:*:*:*:*:*:*:*
broadcom etrust_audit_irecorder 1.5 cpe:2.3:a:broadcom:etrust_audit_irecorder:1.5:sp2:*:*:*:*:*:*
broadcom etrust_audit_irecorder 1.5 cpe:2.3:a:broadcom:etrust_audit_irecorder:1.5:sp3:*:*:*:*:*:*
broadcom etrust_audit_irecorder 8.0 cpe:2.3:a:broadcom:etrust_audit_irecorder:8.0:*:*:*:*:*:*:*
broadcom etrust_identity_minder 8.0 cpe:2.3:a:broadcom:etrust_identity_minder:8.0:*:*:*:*:*:*:*
broadcom etrust_integrated_threat_management 8.0 cpe:2.3:a:broadcom:etrust_integrated_threat_management:8.0:*:*:*:*:*:*:*
broadcom itechnology_igateway <= 4.0.050615 cpe:2.3:a:broadcom:itechnology_igateway:*:*:*:*:*:*:*:*
broadcom unicenter_asset_portfolio_management 11.0 cpe:2.3:a:broadcom:unicenter_asset_portfolio_management:11.0:*:*:*:*:*:*:*
broadcom unicenter_autosys_jm 11.0 cpe:2.3:a:broadcom:unicenter_autosys_jm:11.0:*:*:*:*:*:*:*
broadcom unicenter_service_delivery 11.0 cpe:2.3:a:broadcom:unicenter_service_delivery:11.0:*:*:*:*:*:*:*
broadcom unicenter_service_desk 11.0 cpe:2.3:a:broadcom:unicenter_service_desk:11.0:*:*:*:*:*:*:*
broadcom unicenter_service_desk_knowledge_tools 11.0 cpe:2.3:a:broadcom:unicenter_service_desk_knowledge_tools:11.0:*:*:*:*:*:*:*
broadcom unicenter_service_fulfillment 2.2 cpe:2.3:a:broadcom:unicenter_service_fulfillment:2.2:*:*:*:*:*:*:*
broadcom unicenter_service_metric_analysis 11.0 cpe:2.3:a:broadcom:unicenter_service_metric_analysis:11.0:*:*:*:*:*:*:*
ca brightstor_arcserve_backup 11 cpe:2.3:a:ca:brightstor_arcserve_backup:11:*:windows:*:*:*:*:*
ca brightstor_enterprise_backup 10.0 cpe:2.3:a:ca:brightstor_enterprise_backup:10.0:*:solaris:*:*:*:*:*
ca brightstor_enterprise_backup 10.5 cpe:2.3:a:ca:brightstor_enterprise_backup:10.5:*:solaris:*:*:*:*:*
ca brightstor_enterprise_backup 10.5 cpe:2.3:a:ca:brightstor_enterprise_backup:10.5:*:tru64:*:*:*:*:*
ca brightstor_enterprise_backup 10.5 cpe:2.3:a:ca:brightstor_enterprise_backup:10.5:*:windows_64-bit:*:*:*:*:*
ca etrust_audit_aries 1.5 cpe:2.3:a:ca:etrust_audit_aries:1.5:sp2:*:*:*:*:*:*
ca etrust_audit_aries 1.5 cpe:2.3:a:ca:etrust_audit_aries:1.5:sp3:*:*:*:*:*:*
ca etrust_directory 8.1_web_components cpe:2.3:a:ca:etrust_directory:8.1_web_components:*:*:*:*:*:*:*
ca etrust_secure_content_manager 8.0 cpe:2.3:a:ca:etrust_secure_content_manager:8.0:*:*:*:*:*:*:*
ca unicenter_application_performance_monitor 11.0 cpe:2.3:a:ca:unicenter_application_performance_monitor:11.0:*:*:*:*:*:*:*
ca unicenter_application_server_managment 11.0 cpe:2.3:a:ca:unicenter_application_server_managment:11.0:*:*:*:*:*:*:*
ca unicenter_ca_web_services_distributed_management 11.0 cpe:2.3:a:ca:unicenter_ca_web_services_distributed_management:11.0:*:*:*:*:*:*:*
ca unicenter_exchange_management_console 11.0 cpe:2.3:a:ca:unicenter_exchange_management_console:11.0:*:*:*:*:*:*:*
ca unicenter_management 3.5 cpe:2.3:a:ca:unicenter_management:3.5:*:websphere_mq:*:*:*:*:*
ca unicenter_management 11.0 cpe:2.3:a:ca:unicenter_management:11.0:*:weblogic:*:*:*:*:*
ca unicenter_management 11.0 cpe:2.3:a:ca:unicenter_management:11.0:*:websphere:*:*:*:*:*
ca unicenter_service_catalog_fulfillment_accounting 11.0 cpe:2.3:a:ca:unicenter_service_catalog_fulfillment_accounting:11.0:*:*:*:*:*:*:*
ca unicenter_service_fulfillment 11.0 cpe:2.3:a:ca:unicenter_service_fulfillment:11.0:*:*:*:*:*:*:*
ca unicenter_service_level_management 11.0 cpe:2.3:a:ca:unicenter_service_level_management:11.0:*:*:*:*:*:*:*
ca unicenter_web_server_management 11.0 cpe:2.3:a:ca:unicenter_web_server_management:11.0:*:*:*:*:*:*:*
ca unicenter_web_services_distributed_management 11.0 cpe:2.3:a:ca:unicenter_web_services_distributed_management:11.0:*:*:*:*:*:*:*

References for CVE-2005-3653

cvelogic Threat Intelligence