CVE-2025-34523 (CNNVD-202508-3152)
中文标题:
Arcserve Unified Data Protection 安全漏洞
英文标题:
Arcserve UDP < 10.2 Pre-Authentication Heap Overflow
漏洞描述
中文描述:
Arcserve Unified Data Protection是Arcserve公司的一体化数据和勒索软件保护解决方案。 Arcserve Unified Data Protection 10.2之前版本存在安全漏洞,该漏洞源于网络输入处理存在堆缓冲区溢出,可能导致拒绝服务或远程代码执行。
英文描述:
A heap-based buffer overflow vulnerability exists in the exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when processing attacker-controlled input. By sending specially crafted data, a remote attacker can corrupt heap memory, potentially causing a denial of service or enabling arbitrary code execution depending on the memory layout and exploitation techniques used. This vulnerability is similar in nature to CVE-2025-34522 but affects a separate code path or component. No user interaction is required, and exploitation occurs in the context of the vulnerable process. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Arcserve | Unified Data Protection (UDP) | - | ≤ 10.1 | - |
cpe:2.3:a:arcserve:unified_data_protection_(udp):*:*:*:*:*:*:*:*
|
| arcserve | udp | * | - | - |
cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*
|
| arcserve | udp | 7.0 | - | - |
cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
CRITICALCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34523 |
2025-11-11 15:23:17 | 2025-11-11 07:40:26 |
| NVD | nvd_CVE-2025-34523 |
2025-11-11 15:01:00 | 2025-11-11 07:48:15 |
| CNNVD | cnnvd_CNNVD-202508-3152 |
2025-11-11 15:12:55 | 2025-11-11 08:00:07 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202508-3152
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']