Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3jp-wfm4-c9mv

Опубликовано: 10 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8

Описание

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

EPSS

Процентиль: 64%
0.00474
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

EPSS

Процентиль: 64%
0.00474
Низкий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-470