Impact
The Print Service component of Fiserv Originate Loans Peripherals (formerly Velocity Services) 2021.2.4 uses deprecated .NET Remoting TCP channels that perform unsafe deserialization of untrusted data. This weakness allows an unauthenticated attacker to execute arbitrary code on the affected host. The vulnerability is a direct consequence of the insecure deserialization flaw identified by CWE-502, and it can compromise confidentiality, integrity, and availability of the system if exploited.
Affected Systems
Affected customers are those running the unsupported 2021.2.4 build of the Print Service component. The product is part of Fiserv Originate Loans Peripherals, formerly Velocity Services. No supported releases initially used the same insecure mechanisms; customers should move to version 2025.1 or later, which no longer exposes the insecure .NET Remoting channels.
Risk and Exploitability
The CVSS v3 score is 7.7, indicating high severity, while the EPSS score is less than 1%, suggesting a low probability of exploitation but still possible if the service is reachable from an untrusted network. The vulnerability is not listed in CISA’s KEV catalog. Attackers can target exposed .NET Remoting ports from anywhere on the network; therefore, the primary attack vector is network-based remote exploitation of an unauthenticated service.
OpenCVE Enrichment