CVE-2025-34520 (CNNVD-202508-3157)
中文标题:
Arcserve Unified Data Protection 安全漏洞
英文标题:
Arcserve UDP < 10.2 Authentication Bypass
漏洞描述
中文描述:
Arcserve Unified Data Protection是Arcserve公司的一体化数据和勒索软件保护解决方案。 Arcserve Unified Data Protection 10.2之前版本存在安全漏洞,该漏洞源于身份验证绕过,可能导致未经授权访问。
英文描述:
An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms without valid credentials and access administrator-level features. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Arcserve | Unified Data Protection (UDP) | - | ≤ 10.1 | - |
cpe:2.3:a:arcserve:unified_data_protection_(udp):*:*:*:*:*:*:*:*
|
| arcserve | udp | * | - | - |
cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*
|
| arcserve | udp | 7.0 | - | - |
cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34520 |
2025-11-11 15:23:17 | 2025-11-11 07:40:26 |
| NVD | nvd_CVE-2025-34520 |
2025-11-11 15:01:00 | 2025-11-11 07:48:15 |
| CNNVD | cnnvd_CNNVD-202508-3157 |
2025-11-11 15:12:55 | 2025-11-11 08:00:07 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202508-3157
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']