PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Network Vulnerabilities·Updated Mar 25, 2026

BMC FootPrints - Deserialization of Untrusted Data (RCE)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-71260
8.7
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
FootPrintsby BMC Software, Inc.
20.20.02
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

BMC FootPrints - Deserialization of Untrusted Data (RCE) Scanner | S4E