CVE-2025-34520 Details
Description
An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms without valid credentials and access administrator-level features. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.
A vulnerability allowing authentication bypass has been identified in Arcserve Unified Data Protection (UDP) versions prior to 10.2. This flaw enables unauthenticated attackers to access protected functionalities or user accounts by manipulating request parameters or exploiting logic flaws to bypass login mechanisms. As a result, attackers can gain unauthorized access to administrator-level features.
Users can upgrade to Arcserve UDP 10.2, which includes the necessary patches. For those using Arcserve UDP versions 8.0 through 10.1, patches are available and can be applied. Customers on unsupported versions (UDP 7.x and earlier) should urgently upgrade to UDP 10.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| arcserve udp | < 7.0 >= 8.0, < 10.2 7.0 - 7.0 update_1 7.0 update_2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2025 | Initial Analysis | [email protected] |
| Aug 27, 2025 | New CVE Received | [email protected] |