CVE-2025-34523 is a critical heap-based buffer overflow vulnerability in Arcserve Unified Data Protection (UDP) versions prior to 10.2, specifically affecting network-facing input handling routines. This flaw allows an unauthenticated remote attacker to corrupt heap memory by sending specially crafted data, potentially leading to denial of service or arbitrary code execution. With a CVSS score of 9.8 (CRITICAL), it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered community discussion, highlighting its potential for remote code execution. Organizations are urged to upgrade to UDP 10.2 or apply necessary patches for supported versions (8.0-10.1) immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.0CPE matchmatch criteria | cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:* | ||
>= 8.0, < 10.2CPE matchmatch criteria | cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.