S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 25, 2026

CVE-2025-71260 Scanner

CVE-2025-71260 Scanner - Rce vulnerability in BMC FootPrints

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-71260
8.7
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
FootPrintsby BMC Software, Inc.
20.20.02
Updated Aug 19, 2026View on NVD →
Detail

BMC FootPrints is an IT service management software widely used by IT departments and service providers to streamline their workflows, manage service requests, and automate various IT processes. This software helps organizations improve their operational efficiency by providing a centralized platform for incident management, problem management, and change management. BMC FootPrints is commonly utilized in environments where strong IT governance and compliance are critical, such as corporate, educational, and public sector organizations. It supports integration with other IT service management tools, enhancing the overall IT ecosystem in which it operates. FootPrints is designed to handle complex IT service requirements, making it a vital tool for IT departments aiming to deliver high-quality service to their users and stakeholders.

The Deserialization of Untrusted Data vulnerability allows attackers to execute arbitrary code through the deserialization of maliciously crafted objects. This vulnerability typically arises when an application deserializes objects from untrusted sources without appropriate validation or sanitization. Exploiting this flaw, an attacker could potentially inject harmful payloads that are deserialized into executable code by the application. In the context of BMC FootPrints, this vulnerability can lead to unauthorized execution of commands on the server, severely compromising the security of the application environment. It is a critical vulnerability that needs urgent addressing to prevent attackers from gaining unauthorized access or control over the application and its underlying resources.

This technical security flaw is exploited through the 'aspnetconfig' endpoint in BMC FootPrints, where Java deserialization is mishandled. The endpoint may inadvertently process crafted deserialization payloads that enable code execution. Specifically, the component or parameter vulnerable to this attack is the '__VIEWSTATE' parameter, which is used in HTTP requests to the application. When the application processes a request containing a deserialized object, it might execute arbitrary code embedded in the malicious payload by the attacker. The vulnerability is further exacerbated by the lack of proper authorization checks, allowing exploitation pre-authentication. Thus, even without valid user credentials, an attacker can manipulate the application's deserialization process.

When the Deserialization of Untrusted Data vulnerability is exploited, it can lead to severe consequences, including remote code execution on the affected server. This can allow attackers to take full control of the application, leading to data breaches, unauthorized data manipulation, and the potential for further network penetration. Compromised systems can be used as launch points for additional attacks against other network resources, significantly expanding the attacker's reach. The integrity and availability of the IT services managed by BMC FootPrints could be severely affected, leading to operational downtime and financial losses. Exploiting this vulnerability can also lead to compliance issues, especially in environments that adhere to stringent data protection regulations.

REFERENCES

Solution Advice
  • Immediately upgrade BMC FootPrints to the latest patched version to resolve the deserialization vulnerability.
  • Implement security best practices such as disabling deserialization of data from untrusted sources wherever possible.
  • Use application-level security controls to validate and sanitize data before deserialization.
  • Monitor application logs for suspicious activities that may suggest attempted payload injections.
  • Enhance network security measures to detect and block malicious requests targeting known vulnerability endpoints.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.