CVE-2025-34395

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
10/12/2025
Last modified:
23/12/2025

Description

Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read arbitrary files. This vulnerability can be escalated to remote code execution by retrieving the .NET machine keys.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:barracuda:rmm:*:*:*:*:*:*:*:* 2025.1.1 (excluding)