CVE-2025-34395

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by retrieving the .NET machine keys.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Dec 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 16:16

Updated : 2025-12-12 15:18


NVD link : CVE-2025-34395

Mitre link : CVE-2025-34395

CVE.ORG link : CVE-2025-34395


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')