PT-2025-50338 · Barracuda Networks · Barracuda Service Center

Piotr Bazydlo

·

Published

2025-12-10

·

Updated

2025-12-23

·

CVE-2025-34395

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Barracuda Service Center versions prior to 2025.1.1
Description The Barracuda Service Center, as part of the RMM solution, has a .NET Remoting service exposed that allows an unauthenticated attacker to invoke a method susceptible to path traversal, enabling the reading of arbitrary files. This can be further exploited to achieve remote code execution by obtaining the .NET machine keys.
Recommendations Update Barracuda Service Center to version 2025.1.1 or later.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-34395

Affected Products

Barracuda Service Center