CVE-2025-34520General(arcserve / udp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms without valid credentials and access administrator-level features. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udp

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
udp

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-01: 103-01
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Stratosberry@stratosberry
    General

    @SinSinology I recently came across an Arcserve UDP that appears to be vulnerable to CVE-2025-34520 in an internal engagement. Any details you can share with me please regarding the auth bypass?

    Post summary

    The user reports encountering Arcserve UDP vulnerability CVE-2025-34520 and requests details about an authentication bypass, but no further technical or contextual information is provided.

    00000173
    21 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apparcserveudp---
Apparcserveudp7.0--
Apparcserveudp7.0--
Apparcserveudp7.0--

Explore more