A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsani…

cve CVE-2025-34521 1 source, 1 claim · Watch

NVD writes:
A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versi… the claim
Severity
MEDIUM NVD
CVSS
5.4 NVD
Vendor
Arcserve NVD
Product
Unified Data Protection (UDP) NVD
CWE
CWE-79 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2025-08-27first spoke of it: A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.NVD

A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

What it is to other things

affectsarcserve/udp
NVD
made_byarcserve
NVD

In words only, so not counted until a person confirms one:

affectsarcserve/unified_data_protection_udp
NVD says “Arcserve · Unified Data Protection (UDP)”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.4
receipt
Source
NVD
Its words
5.4
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4
cvss4
NVD4.8
receipt
Source
NVD
Its words
4.8
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTC4.8
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-79
receipt
Source
NVD
Its words
CWE-79
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCWE-79
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDUnified Data Protection (UDP)
receipt
Source
NVD
Its words
Unified Data Protection (UDP)
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCUnified Data Protection (UDP)
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDArcserve
receipt
Source
NVD
Its words
Arcserve
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCArcserve
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "modules": [
              "Web interface input handling and response rendering logic"
            ],
            "product": "Unified Data Protection (UDP)",
            "vendor": "Arcserve",
            "versions": [
              {
                "status": "unaffected",
                "version": "10.2"
              },
              {
                "lessThanOrEqual": "10.1",
                "status": "affected",
                "version": "8.0",
                "versionType": "custom"
              },
              {
                "lessThanOrEqual": "7.*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "53D70153-E6B7-4D27-83AA-77817EBBBC3E",
                "versionEndExcluding": "7.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "7644D867-3950-4EBF-9CBE-644458C26801",
                "versionEndExcluding": "10.2",
                "versionStartIncluding": "8.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1CAB17ED-9FBC-475F-8206-3BC8E672C719",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_1:*:*:*:*:*:*",
                "matchCriteriaId": "8672F05B-B0FC-4A81-8D5B-2A7DE8C6D92D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:arcserve:udp:7.0:update_2:*:*:*:*:*:*",
                "matchCriteriaId": "1379C0DE-8BB0-47FF-AE56-6E54F125E5A0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad de cross-site scripting (XSS) reflejado existe en la interfaz web de Arcserve Unified Data Protection (UDP), donde la entrada de usuario no saneada se refleja incorrectamente en las respuestas HTTP. Esta falla permite a atacantes remotos con bajos privilegios crear enlaces maliciosos que, al ser visitados por otro usuario, ejecutan JavaScript arbitrario en el navegador de la víctima. La explotación exitosa puede llevar a secuestro de sesión, robo de credenciales u otros impactos del lado del cliente. La vulnerabilidad requiere interacción del usuario y ocurre dentro de un contexto de navegador compartido. Esta vulnerabilidad afecta a todas las versiones de UDP anteriores a la 10.2. UDP 10.2 incluye los parches necesarios y no requiere ninguna acción. Las versiones 8.0 a 10.1 son compatibles y requieren la aplicación de parches o la actualización a la 10.2. Las versiones 7.x y anteriores no son compatibles o están fuera de mantenimiento y deben actualizarse a la 10.2 para remediar el problema."
      }
    ],
    "id": "CVE-2025-34521",
    "lastModified": "2026-09-26T00:10:00.127",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.3,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "ACTIVE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-34521",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-08-28T14:22:20.715713Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-08-27T22:15:57.870",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.arcserve.com/s/article/Important-Security-Bulletin-Must-read-for-all-Arcserve-UDP-customers-on-all-versions"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection (UDP), where unsanitized user input is improperly reflected in HTTP responses. This flaw allows remote attackers with low privileges to craft malicious links that, when visited by another user, execute arbitrary JavaScript in the victim’s browser. Successful exploitation may lead to session hijacking, credential theft, or other client-side impacts. The vulnerability requires user interaction and occurs within a shared browser context. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.
zetlyn/cve-nvd · 2025-08-27
automatable no cvss 5.4 cvss4 4.8 cvss4_vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N cwe CWE-79 exploitation none product Unified Data Protection (UDP) severity MEDIUM status Analyzed technical_impact partial vendor Arcserve source