S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 20, 2026

CVE-2025-71257 Scanner

CVE-2025-71257 Scanner - Authentication Bypass vulnerability in BMC FootPrints

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-71257
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and gain unauthorized access to application data and modify system resources. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
FootPrintsby BMC Software, Inc.
20.20.02
Updated Sep 9, 2026View on NVD →
Detail

BMC FootPrints is a service management software commonly used in IT departments to manage and automate service requests, incidents, and changes within an organization. Developed by BMC Software, it assists businesses in streamlining their service management processes and enhancing productivity. The software is typically deployed by enterprises that need to handle complex IT service management tasks efficiently. Its multi-functional range includes service desk operations, incident management, and IT asset management. This software supports organizations in improving communication between service desks and end-users, ensuring quicker response times. It aims to enhance customer satisfaction and operational efficiency in IT service delivery.

The vulnerability in question is an Authentication Bypass, specifically affecting the password reset functionality of BMC FootPrints. This flaw allows unauthenticated attackers to exploit the password reset endpoint to obtain a valid SEC_TOKEN session cookie. As a result, attackers can bypass the usual authentication mechanisms without rightful access permissions. This vulnerability opens the door for potential exploitation of other security flaws, creating a chain of vulnerabilities that could severely compromise the affected system's security. Exploiting this vulnerability could enable attackers to access restricted areas of the application, posing a significant risk to sensitive data integrity and confidentiality.

The technical aspect of this vulnerability centers around the password reset functionality at the /footprints/servicedesk/passwordreset/request/ endpoint. An attacker can exploit this endpoint to request a SEC_TOKEN session cookie, circumventing standard authentication protocols. All BMC FootPrints versions from 20.20.02 to 20.24.01.001 are susceptible to this flaw. The vulnerability potentially facilitates further exploitation of the system's security, as it could be part of a larger attack chain. This attack vector particularly affects the service desk module, crucial for IT service management, and could be used to obtain unauthorized access to system resources.

When exploited, this authentication bypass vulnerability allows attackers to gain unauthorized access to sensitive application features and information. The attackers can manipulate or alter application data, leading to significant data breaches. The compromised system's resources could further facilitate the launch of additional attacks such as remote code execution or server-side request forgery. Due to the nature of this vulnerability, the potential effects include the disruption of service operations and loss of sensitive business data, compromising the organization's overall security posture.

REFERENCES

Solution Advice
  • Apply the hotfixes released by BMC on September 2, 2025, for all affected branches.
  • Ensure that your BMC FootPrints installation is updated to the latest patched version.
  • Regularly monitor and audit access logs to detect unauthorized access attempts.
  • Implement stricter access control measures and limit password reset functionalities.
  • Educate staff on secure password management and authentication practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-71257 Scanner - Authentication Bypass vulnerability in BMC FootPrints | S4E