CVE-2025-71260
PoC moderateAuthenticated ASP.NET VIEWSTATE Deserialization RCE in BMC FootPrints ITSM
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data flaw (CWE-502) in the ASP.NET servlet's handling of the VIEWSTATE parameter. An authenticated attacker with low privileges can submit crafted serialized objects in the VIEWSTATE parameter over the network, with no user interaction required. Successful exploitation yields arbitrary code execution, allowing the attacker to fully compromise the ITSM application and its host (high impact to confidentiality, integrity, and availability). Organizations running any affected FootPrints ITSM release are exposed, particularly where the web interface is reachable from untrusted networks. No confirmed in-the-wild exploitation has been reported and it is not in CISA KEV, but a public PoC exists (WatchTowr Labs research, which also describes pre-authentication RCE chains against FootPrints), and the 34.4% EPSS score (98th percentile) indicates an elevated probability of exploitation within 30 days.
What to do: Upgrade each deployment to the remediation hotfix matching its baseline release, choosing from the vendor-listed builds (20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01). Until patched, restrict network access to the FootPrints web interface, verify ASP.NET VIEWSTATE integrity (MAC/encryption) settings are enabled, and review web logs for suspicious POST requests to the ASP.NET servlet.
| bmc FootPrints ITSM | 20.20.02 through 20.24.01.001 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
- Vendors
- bmc
- Products
- footprints
- Weakness
- CWE-502
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X