BMC FootPrints - Authentication Bypass
CVE-2025-71257
Verified
Description
BMC FootPrints versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability in the password reset functionality. Unauthenticated attackers can access the /footprints/servicedesk/passwordreset/request/ endpoint to obtain a valid SEC_TOKEN session cookie without proper authentication. This vulnerability enables exploitation of other vulnerabilities in the chain including CVE-2025-71258 and CVE-2025-71259 (SSRF) and CVE-2025-71260 (deserialization RCE).
Severity
Medium
CVSS Score
6.5
Exploit Probability
45%
Affected Product
footprints
Published Date
March 18, 2026
Template Author
watchtowr, dhiyaneshdk
CVE-2025-71257.yaml
6.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVE ID:
cve-2025-71257
CWE ID:
cwe-287
Remediation Steps
Apply the hotfixes released by BMC on September 2, 2025 for all affected branches. Update to the latest patched version of BMC FootPrints.