8.4

CVSS4.0

CVE-2025-55118 - BMC Control-M/Agent memory corruption in SSL/TLS communication

Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n"; * Control-M/Agent 9.0.21 and 9.0.22: Age…

πŸ“… Published: Sept. 16, 2025, 12:23 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:23 p.m.

6.3

CVSS4.0

CVE-2025-55117 - BMC Control-M/Agent buffer overflow in SSL/TLS communication

A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n";…

πŸ“… Published: Sept. 16, 2025, 12:22 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:22 p.m.

9.3

CVSS4.0

CVE-2025-55116 - BMC Control-M/Agent buffer overflow local privilege escalation

A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.

πŸ“… Published: Sept. 16, 2025, 12:22 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:22 p.m.

9.3

CVSS4.0

CVE-2025-55115 - BMC Control-M/Agent path traversal local privilege escalation

A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was …

πŸ“… Published: Sept. 16, 2025, 12:21 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:21 p.m.

6.9

CVSS4.0

CVE-2025-55114 - BMC Control-M/Agent improper IP address filtering order

The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default conditions (e.g. CVE-20…

πŸ“… Published: Sept. 16, 2025, 12:20 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:20 p.m.

9.5

CVSS4.0

CVE-2025-55113 - BMC Control-M/Agent unescaped NULL byte in access control list checks

If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification sto…

πŸ“… Published: Sept. 16, 2025, 12:20 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:20 p.m.

7.6

CVSS4.0

CVE-2025-55112 - BMC Control-M/Agent hardcoded Blowfish keys

Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between th…

πŸ“… Published: Sept. 16, 2025, 12:19 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:19 p.m.

5.1

CVSS4.0

CVE-2025-10546 - Cross-Site Scripting (XSS) Vulnerability in PPC XPON ONT Wi-Fi Router

This vulnerability exist in PPC 2K15X Router, due to improper input validation for the Common Gateway Interface (CGI) parameters at its web management portal. A remote attacker could exploit this vulnerability by injecting malicious JavaScript into the vulnerable parameter, leading to a reflected C…

πŸ“… Published: Sept. 16, 2025, 12:18 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:18 p.m.

5.7

CVSS4.0

CVE-2025-55111 - BMC Control-M/Agent insecure default file permissions

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to…

πŸ“… Published: Sept. 16, 2025, 12:18 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:18 p.m.

5.7

CVSS4.0

CVE-2025-55110 - BMC Control-M/Agent hardcoded default keystore password

Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password.

πŸ“… Published: Sept. 16, 2025, 12:16 p.m. πŸ”„ Last Modified: Sept. 16, 2025, 12:16 p.m.
Total resulsts: 310060
Page 7 of 31,006
Β« previous page Β» next page
Filters