PT-2019-18984 · Bmc · Bmc Patrol Agent
B0Yd
+1
·
Published
2019-05-20
·
Updated
2022-03-30
·
CVE-2019-8352
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BMC PATROL Agent versions prior to 11.3.01
Description
The issue allows an attacker to capture network traffic, decrypt user credentials, and potentially execute code or escalate privileges on the network. This is due to the use of a static encryption key for encrypting and decrypting user credentials sent over the network to managed PATROL Agent services.
Recommendations
For versions prior to 11.3.01, update to version 11.3.01 or later to resolve the issue.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Patrol Agent