CVE-2025-34522 (CNNVD-202508-3153)
中文标题:
Arcserve Unified Data Protection 安全漏洞
英文标题:
Arcserve UDP < 10.2 Pre-Authentication Heap Overflow
漏洞描述
中文描述:
Arcserve Unified Data Protection是Arcserve公司的一体化数据和勒索软件保护解决方案。 Arcserve Unified Data Protection 10.2之前版本存在安全漏洞,该漏洞源于堆缓冲区溢出,可能导致远程代码执行。
英文描述:
A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to application crashes or remote code execution. Exploitation occurs in the context of the affected process and does not require user interaction. The vulnerability poses a high risk due to its pre-authentication nature and potential for full compromise. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Arcserve | Unified Data Protection (UDP) | - | ≤ 10.1 | - |
cpe:2.3:a:arcserve:unified_data_protection_(udp):*:*:*:*:*:*:*:*
|
| arcserve | udp | * | - | - |
cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*
|
| arcserve | udp | 7.0 | - | - |
cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34522 |
2025-11-11 15:23:17 | 2025-11-11 07:40:26 |
| NVD | nvd_CVE-2025-34522 |
2025-11-11 15:01:00 | 2025-11-11 07:48:15 |
| CNNVD | cnnvd_CNNVD-202508-3153 |
2025-11-11 15:12:55 | 2025-11-11 08:00:07 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202508-3153
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']