PT-2019-18984 · Bmc · Bmc Patrol Agent
B0Yd
+1
·
Publicado
2019-05-20
·
Atualizado
2022-03-30
·
CVE-2019-8352
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BMC PATROL Agent versions prior to 11.3.01
Description
The issue allows an attacker to capture network traffic, decrypt user credentials, and potentially execute code or escalate privileges on the network. This is due to the use of a static encryption key for encrypting and decrypting user credentials sent over the network to managed PATROL Agent services.
Recommendations
For versions prior to 11.3.01, update to version 11.3.01 or later to resolve the issue.
Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bmc Patrol Agent