CVE-2025-34395: Barracuda RMM < 2025.1.1 Service Center .NET Remoting Path Traversal RCE
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by retrieving the .NET machine keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34395?
CVE-2025-34395 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-34395?
To fix CVE-2025-34395, upgrade to Barracuda Service Center version 2025.1.1 or later.
What are the risks associated with CVE-2025-34395?
The risks associated with CVE-2025-34395 include unauthorized access to sensitive files and potential remote code execution.
Who is affected by CVE-2025-34395?
CVE-2025-34395 affects all versions of Barracuda Service Center prior to 2025.1.1.
What type of attack vector does CVE-2025-34395 present?
CVE-2025-34395 presents an attack vector through an unauthenticated path traversal vulnerability in the .NET Remoting service.