CVE-2025-71260 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 19, 2026
BMC FootPrints ITSM - Remote Code Execution
Overview
BMC FootPrints ITSM 20.20.02 through 20.24.01.001 contains an insecure deserialization vulnerability in ASP.NET servlet VIEWSTATE handling, letting authenticated attackers execute arbitrary code remotely, exploit requires authentication.
Severity & Score
Impact
Authenticated attackers can execute arbitrary code remotely, fully compromising the application.
Mitigation
Apply hotfixes 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01.
References
- https://docs.bmc.com/xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/Release-notes/2024-Release-01-Patch-2/
- https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/
- https://www.vulncheck.com/advisories/bmc-footprints-itsm-viewstate-deserialization-rce
Social Media Activity(2 posts)
š CVE-2025-71260 - High (8.8) BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply cr... š https://www.thehackerwire.com/vulnerability/CVE-2025-71260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2025-71260 - High (8.8) BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply cr... š https://www.thehackerwire.com/vulnerability/CVE-2025-71260/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2025-71260
- Severity
- High
- CVSS Score
- 8.8
- Type
- insecure_deserialization
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-502
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H