← Vulnerability feed

Vulnerability record · CVE-2025-34522 · published 27 August 2025

CVE-2025-34522: Arcserve udp heap-based buffer overflow vulnerability

Arcserve · Udp

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to application crashes or remote code execution. Exploitation occurs in the context of the affected process and does not require user interaction. The vulnerability poses a high risk due to its pre-authentication nature and potential for full compromise. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

9.2 CVSS 4.0 Critical EPSS 0.56% · top 55.9% CWE-122 · Heap-based buffer overflow
9.2CVSS 4.0 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
26 Sep 2026Last modified by NVD

Description

A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to overwrite heap memory, potentially leading to application crashes or remote code execution. Exploitation occurs in the context of the affected process and does not require user interaction. The vulnerability poses a high risk due to its pre-authentication nature and potential for full compromise. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-34522 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2015-4068Arcserve UDP servlet path traversal exposes files and causes DoSArcserve UDP before 5.0 Update 4 contains a directory traversal flaw in the reportFileServlet and exportServlet servlets. A crafted file path lets a …KEVEPSS 64%analysed9.8CVE-2024-0799Arcserve udp improper authentication vulnerabilityAn authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app…EPSS 4.3%9.8CVE-2023-42000Arcserve udp path traversal vulnerabilityArcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthentic…EPSS 1.5%9.8CVE-2023-41998Arcserve udp unrestricted file upload vulnerabilityArcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows …EPSS 15%9.8CVE-2023-41999Arcserve udp improper authentication vulnerabilityAn authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifie…EPSS 1.4%9.8CVE-2023-26258Arcserve udp incorrect authorization vulnerabilityArcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID …EPSS 40%9.2CVE-2025-34523Arcserve udp heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw …EPSS 0.53%8.8CVE-2024-0800Arcserve udp unrestricted file upload vulnerabilityA path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.ser…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2025-34522), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.