« Volver al listado

CVE-2025-34522

Estado: AnalizadaCrítica (9.2)—

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to application crashes or remote code execution. Exploitation occurs in the context of the affected process and does not require user interaction. The vulnerability poses a high risk due to its pre-authentication nature and potential for full compromise.

Leer descripción completaMostrar menos

This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Buffer overflow en parsing sin autenticación (AV:N, PR:N) permite RCE o crash. CVSS CRITICAL con VC:H/VI:H/VA:H confirma ejecución remota de código en contexto del proceso.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-34522",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-34522",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-29T03:55:20.727536Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 9.2,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "vendor": "Arcserve",
          "modules": [
            "input parsing logic"
          ],
          "product": "Unified Data Protection (UDP)",
          "versions": [
            {
              "status": "unaffected",
              "version": "10.2"
            },
            {
              "status": "affected",
              "version": "8.0",
              "versionType": "custom",
              "lessThanOrEqual": "10.1"
            },
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "7.*"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-27T22:15:58.040",
  "references": [
    {
      "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to application crashes or remote code execution. Exploitation occurs in the context of the affected process and does not require user interaction. The vulnerability poses a high risk due to its pre-authentication nature and potential for full compromise. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de desbordamiento de búfer basado en heap-based existe en la lógica de análisis de entrada de Arcserve Unified Data Protection (UDP). Este fallo puede ser activado sin autenticación enviando una entrada especialmente diseñada al sistema objetivo. La comprobación de límites incorrecta permite a un atacante sobrescribir la memoria heap, lo que podría llevar a fallos de la aplicación o a la ejecución remota de código. La explotación ocurre en el contexto del proceso afectado y no requiere interacción del usuario. La vulnerabilidad plantea un alto riesgo debido a su naturaleza de pre-autenticación y su potencial de compromiso total. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
    }
  ],
  "lastModified": "2026-09-26T00:10:00.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
              "versionEndExcluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
              "versionEndExcluding": "10.2",
              "versionStartIncluding": "8.0"
            },
            {
              "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719"
            },
            {
              "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D"
            },
            {
              "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosure@vulncheck.com"
}