Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-34393

Опубликовано: 10 дек. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:*
Версия до 2025.1.1 (исключая)

EPSS

Процентиль: 64%
0.00474
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-470

Связанные уязвимости

CVSS3: 9.8
github
около 2 месяцев назад

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify the name of an attacker-controlled WSDL service, leading to insecure reflection. This can result in remote code execution through either invocation of arbitrary methods or deserialization of untrusted types.

EPSS

Процентиль: 64%
0.00474
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-470