PT-2025-45096 · Bmc · Bmc Control-M/Agent

CVE-2025-55108

·

Publicado

2025-11-05

·

Atualizado

2025-11-12

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BMC Control-M/Agent (affected versions not specified)
Description The Control-M/Agent is susceptible to unauthenticated remote code execution, arbitrary file read and write, and other unauthorized actions when mutual SSL/TLS authentication is not enabled, which is the default configuration. The vendor indicates that this issue arises only when documented security best practices are not followed, specifically the configuration of SSL/TLS between the Control-M Server and Agent.
Recommendations Enable mutual SSL/TLS authentication to mitigate the risk. Configure SSL/TLS between Control-M Server and Agent, following the vendor's security best practices.

Correção

RCE

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-55108

Produtos afetados

Bmc Control-M/Agent