---
id: CVE-2025-71260
title: >-
  BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a
  deserialization of untrusted data vulnerability in the ASP.NET servlet's
  VIEWSTATE handling that allows authenticated attackers to execute arbitrary
  code
summary: >-
  BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a
  deserialization of untrusted data vulnerability in the ASP.NET servlet's
  VIEWSTATE handling that allows authenticated attackers to execute arbitrary
  code. Attackers can…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: bmc
product: footprints
affected:
  - 'footprints >= 20.20.02, <= 20.24.01.001'
published: '2026-03-19'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71260'
references:
  - url: >-
      https://docs.bmc.com/xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/Release-notes/2024-Release-01-Patch-2/
    label: disclosure@vulncheck.com
  - url: >-
      https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/bmc-footprints-itsm-viewstate-deserialization-rce
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.3436
epssPercentile: 0.98341
ingestedAt: '2026-08-06T15:59:59.366Z'
---

## Overview

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

## Affected

- `footprints >= 20.20.02, <= 20.24.01.001`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
