216.73.216.233

CVE-2025-55108

· Published 05/11/2025 09:15 · Modified 18/11/2025 15:16

Labels: CVE-2025-55108 2025-11-05CVE-2025-55108CWE-306[email protected]

Essential information

Published
05/11/2025 09:15
Modified
18/11/2025 15:16
Author
Creator
CVSS
9.5 CRITICAL (v3) 9.5 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration). NOTE:  * The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use security best practices such as configuring SSL/TLS between Control-M Server and Agent. * The vendor notifies that Control-M/Agent is not impacted in Control-M SaaS

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References