Описание
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.
Ссылки
- Release Notes
- ExploitThird Party Advisory
- Product
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2025.1.1 (исключая)
cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00782
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-36
Связанные уязвимости
CVSS3: 9.8
github
около 2 месяцев назад
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and remote code execution via webshell upload.
EPSS
Процентиль: 73%
0.00782
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-36