Описание
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by retrieving the .NET machine keys.
Уязвимые конфигурации
Конфигурация 1Версия до 2025.1.1 (исключая)
cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00141
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
около 2 месяцев назад
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by retrieving the .NET machine keys.
EPSS
Процентиль: 34%
0.00141
Низкий
7.5 High
CVSS3
Дефекты
CWE-22