Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-71260

62
FAUCET Score

CVE-2025-71260 is a high-severity deserialization of untrusted data vulnerability impacting BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001. This flaw, found in the ASP.NET servlet's VIEWSTATE handling, allows an authenticated attacker to achieve remote code execution and fully compromise the application. With a CVSS v3.1 score of 8.8 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, requiring only low privileges. Currently, there is no evidence of active exploitation, nor are public exploit codes available, and community discussion remains minimal.

Impacted Technologies

VendorProductVersion(s)CPE
>= 20.20.02, <= 20.24.01.001CPE matchmatch criteria
cpe:2.3:a:bmc:footprints_itsm:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
34.36%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-71260 · Mar 19, 2026
This CVE's current EPSS score of 0.3436 is in the 97th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

3cxvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (5)

nutanixllm-nutanix-ff1d0c9e386f23fcCRITICAL

BMC FootPrints Remote Code Execution (CVE-2025-71260)

Mar 19, 2026
horillallm-horilla-e42c35bbb793f595CRITICAL

BMC FootPrints Remote Code Execution (CVE-2025-71260)

Mar 19, 2026
inveniosoftwarellm-inveniosoftware-25b9d9a6d0e01ac5CRITICAL

BMC FootPrints Remote Code Execution (CVE-2025-71260)

Mar 19, 2026
jitsillm-jitsi-815653230110d9bfCRITICAL

BMC FootPrints Remote Code Execution (CVE-2025-71260)

Mar 19, 2026
3cxllm-3cx-d4065bebc14953e6CRITICAL

BMC FootPrints Remote Code Execution (CVE-2025-71260)

Mar 19, 2026

References

docs.bmc.com / xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/Release-notes/2024-Release-01-Patch-2
Patch
labs.watchtowr.com / thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains
ExploitThird Party Advisory
vulncheck.com / advisories/bmc-footprints-itsm-viewstate-deserialization-rce
Third Party Advisory